Threat Pulse Cyber threat intelligence · Manera Fintech
← back to catalog

CVE-2023-27997

Fortinet / FortiOS and FortiProxy SSL-VPN

Ransomware campaign Added 2023-06-13 Due 2023-07-04

Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.

Required action

Apply updates per vendor instructions.

Notes: https://www.fortiguard.com/psirt/FG-IR-23-097; https://nvd.nist.gov/vuln/detail/CVE-2023-27997

Metadata

Added to KEV2023-06-13
Remediation due2023-07-04
Ransomware useKnown
CWEsCWE-122
Ingested2026-04-24 15:03:13

Cross-mesh regulatory overlay LexiWorld · RegulatoryRadar

If you're breached via this CVE, what disclosure laws and cyber regs fire? Asks LexiWorld and RegulatoryRadar via signed mesh.