1 min read
Critical Vulnerabilities in Microsoft and Fortinet Products
Published 04/13/2023 I. Targeted Entities Windows and Fortinet systems II. Introduction Several critical vulnerabilities were discovered in both...
7 min read
Cyber Florida SOCAP Team
:
Updated on August 14, 2026
Published 03/14/2023
Multiple vulnerabilities have recently been identified in Fortinet products. These products are designed to provide network security solutions that protect your network, data, and users from constantly emerging threats. (Fortiguard 2023)
Fortinet has recently revealed a highly severe vulnerability, marked as “Critical,” that affects both FortiOS and FortiProxy. This flaw allows an unauthenticated attacker to run arbitrary code or launch a denial-of-service (DoS) attack against the graphical user interface (GUI) of the affected systems by using specially crafted requests. (Toulas, 2023)
The vulnerability is recognized as CVE-2023-25610 and has a CVSS v3 score of 9.3, classified as critical. A buffer underflow vulnerability like this occurs when a program attempts to read more data from a memory buffer than is available. This leads to accessing adjacent memory locations, potentially resulting in unstable behavior or system crashes. Fortinet’s telemetry data revealed no evidence that threat actors exploited the vulnerability in real-world attacks. (Multiple Vulnerabilities in Fortinet Products Could Allow for Arbitrary Code 2023)
According to Fortinet’s security bulletin, 50 device models are not affected by the arbitrary code execution aspect of the vulnerability. However, these same models are still vulnerable to the denial-of-service part, even if they are running a vulnerable version of FortiOS. (Toulas, 2023)
Affected Products:
FortiOS version 7.2.0 through 7.2.3
FortiOS version 7.0.0 through 7.0.9
FortiOS version 6.4.0 through 6.4.11
FortiOS version 6.2.0 through 6.2.12
FortiOS 6.0 all versions
FortiProxy version 7.2.0 through 7.2.2
FortiProxy version 7.0.0 through 7.0.8
FortiProxy version 2.0.0 through 2.0.12
FortiProxy 1.2 all versions
FortiProxy 1.1 all versions
For those who cannot apply the updates immediately, Fortinet recommends either disabling the HTTP/HTTPS administrative interface or restricting the IP addresses that can access it remotely. Instructions for implementing these workarounds, which also apply to non-default port usage, are provided in the security advisory.
Threat actors are actively searching for critical-severity vulnerabilities in Fortinet products, particularly those that do not require authentication to exploit. These vulnerabilities provide attackers with a means of gaining initial access to corporate networks. As a result, it is critical to address this vulnerability promptly. (Toulas, 2023)
According to a Bleeping Computer article published on March 15, 2023, a new vulnerability in FortiOS, the operating system of Fortinet firewalls, is being actively exploited in the wild to attack government networks. The vulnerability, designated as CVE-2023-41328, is a zero-day vulnerability, meaning it was unknown to the vendor and the public until it was exploited by threat actors.
The attack appears to be highly targeted, aimed at specific government agencies. The attackers used the vulnerability to gain access to the victim’s network and install a backdoor that allowed them to exfiltrate data and execute commands on the compromised systems.
Fortinet has released a patch for the vulnerability and is urging all customers to update their systems immediately. The company has also stated that it is working closely with law enforcement and other relevant authorities to investigate the attacks and identify the perpetrators.
Contributing Security Analysts: EJ Bulut
1 min read
Published 04/13/2023 I. Targeted Entities Windows and Fortinet systems II. Introduction Several critical vulnerabilities were discovered in both...
1 min read
Originally published: 11/12/2024 I. Targeted Entities Fortinet FortiManager Customer Managed Service Providers II. Introduction A critical...
1 min read
Originally Published December 8, 2025