Cyber Resilience

CVE-2023-22639

Memory Safety in Fortinet Fortiproxy 1.0.0 – 1.0.7

Published
13 June 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 6.7
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0019 9th percentile
Risk Priority 45 floored blend · peak EPSS

Summary

CVE-2023-22639 is a medium-severity Out-of-bounds Write (CWE-787) vulnerability in Fortinet Fortiproxy. Its CVSS base score is 6.7 (Medium).

Operationally, ranked at the 9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all…

more

versions 2.0, FortiProxy all versions 1.2, FortiProxy all versions 1.1, FortiProxy all versions 1.0 allows attacker to escalation of privilege via specifically crafted commands.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-21762Same product: Fortinet Fortios
CVE-2023-22640Same product: Fortinet Fortios
CVE-2018-13383Same product: Fortinet Fortios
CVE-2023-42789Same product: Fortinet Fortios
CVE-2023-33308Same product: Fortinet Fortios
CVE-2024-52963Same product: Fortinet Fortios
CVE-2023-46720Same product: Fortinet Fortios
CVE-2024-23110Same product: Fortinet Fortios
CVE-2024-26010Same product: Fortinet Fortios
CVE-2023-29182Same product: Fortinet Fortios

Affected Assets

fortinet
fortiproxy
7.2.0, 7.2.1, 7.2.2 · 1.0.0 — 1.0.7 · 1.1.0 — 1.1.6 · 1.2.0 — 1.2.13
fortinet
fortios
6.0.0 — 6.0.17 · 6.2.0 — 6.2.15 · 6.4.0 — 6.4.12

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-787

Out-of-bounds writes that corrupt control flow or inject shellcode are rendered non-executable by the same memory protections.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure-development practices (static analysis, bounds checking, code review) are the primary means of preventing out-of-bounds writes.

ID.RA-01 partial match
prevents

Vulnerability scanning and recording can discover out-of-bounds write flaws so they can be remediated.

PR.PS-02 partial match
prevents

Patching or replacing vulnerable software directly eliminates known instances of this coding weakness.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

detects

Security testing in development and acceptance can detect and prevent out-of-bounds write defects.

prevents

Secure development life cycle mandates practices that prevent out-of-bounds writes.

prevents

Application security requirements can specify bounds-checking and safe memory handling.

prevents

Secure architecture and engineering principles reduce the likelihood of buffer overflows.

prevents

Secure coding directly addresses out-of-bounds writes through language choice and coding standards.

prevents

Change management can enforce review gates that catch unsafe memory operations before deployment.

References