CVE-2023-45584

A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13 allows a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.4.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*

History

14 Jan 2026, 10:16

Type Values Removed Values Added
Summary (en) A double free vulnerability [CWE-415] in Fortinet FortiOS version 7.4.0, version 7.2.0 through 7.2.5 and before 7.0.12, FortiProxy version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.13 and FortiPAM version 1.1.0 through 1.1.2 and before 1.0.3 allows a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests. (en) A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13 allows a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.

14 Aug 2025, 01:03

Type Values Removed Values Added
First Time Fortinet fortipam
Fortinet
Fortinet fortios
Fortinet fortiproxy
References () https://fortiguard.fortinet.com/psirt/FG-IR-23-209 - () https://fortiguard.fortinet.com/psirt/FG-IR-23-209 - Vendor Advisory
CPE cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

13 Aug 2025, 17:33

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de doble liberación [CWE-415] en Fortinet FortiOS versión 7.4.0, versión 7.2.0 a 7.2.5 y anteriores a 7.0.12, FortiProxy versión 7.4.0 a 7.4.1, versión 7.2.0 a 7.2.7 y anteriores a 7.0.13 y FortiPAM versión 1.1.0 a 1.1.2 y anteriores a 1.0.3 permite a un atacante privilegiado ejecutar código o comandos a través de solicitudes HTTP o HTTPS manipuladas.

12 Aug 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-12 19:15

Updated : 2026-01-14 10:16


NVD link : CVE-2023-45584

Mitre link : CVE-2023-45584

CVE.ORG link : CVE-2023-45584


JSON object : View

Products Affected

fortinet

  • fortiproxy
  • fortipam
  • fortios
CWE
CWE-415

Double Free