A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13 allows a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-23-209 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
14 Jan 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13 allows a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests. |
14 Aug 2025, 01:03
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Fortinet fortipam
Fortinet Fortinet fortios Fortinet fortiproxy |
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-23-209 - Vendor Advisory | |
| CPE | cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.4.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
13 Aug 2025, 17:33
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
12 Aug 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-08-12 19:15
Updated : 2026-01-14 10:16
NVD link : CVE-2023-45584
Mitre link : CVE-2023-45584
CVE.ORG link : CVE-2023-45584
JSON object : View
Products Affected
fortinet
- fortiproxy
- fortipam
- fortios
CWE
CWE-415
Double Free
