June 13, 2023, 3:08 a.m. | Satnam Narang

Cyber Exposure Alerts www.tenable.com

CVE-2023-27997: Heap-Based Buffer Overflow in Fortinet FortiOS and FortiProxy SSL-VPN (XORtigate)

Fortinet says a critical flaw in its SSL-VPN product may have been exploited in the wild in a limited number of cases. Organizations are strongly encouraged to apply these patches immediately.


Background


On June 12, Fortinet published an advisory (FG-IR-23-097) for a critical vulnerability in FortiOS and FortiProxy:










CVEDescriptionCVSSv3Severity
CVE-2023-27997FortiOS and FortiProxy Heap Buffer Overflow in SSL-VPN9.2Critical

In addition to CVE-2023-27997, Fortinet …

advisory buffer buffer overflow cases critical critical flaw cve exploited flaw fortinet fortinet fortios fortios fortiproxy june may organizations overflow patches product ssl vpn

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Information Security Engineer, Sr. (Container Hardening)

@ Rackner | San Antonio, TX

BaaN IV Techno-functional consultant-On-Balfour

@ Marlabs | Piscataway, US

Senior Security Analyst

@ BETSOL | Bengaluru, India

Security Operations Centre Operator

@ NEXTDC | West Footscray, Australia

Senior Network and Security Research Officer

@ University of Toronto | Toronto, ON, CA