CVE-2024-23113
KEVCRITICAL 9.8EPSS 61.7%
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 61.72% chance of exploitation in the next 30 days, 99th percentile
- CISA KEV
- added 2024-10-09
- Published
- 2024-02-15
- Updated
- 2025-10-21
Proof-of-concept exploits (8)
- CheckCve2/CVE-2024-231131★ · 2024-10-11
- MAVRICK-1/cve-2024-23113-test-env1★ · 2025-07-02
- p33d/CVE-2024-2311311★ · 2024-10-27
- puckiestyle/CVE-2024-231131★ · 2024-10-31
- valornode/CVE-2024-231130★ · 2025-05-02
- watchtowrlabs/Fortijump-Exploit-CVE-2024-4757597★ · 2024-11-14
- MinhPham123456789/PoC-CVE-2024-23113
- ownouwa/cve-2024-23113-poc