GPU VulnDB

Database/Control plane, storage & DevOps

Fortinet FortiOS / FortiProxy SSL-VPN: A heap-based buffer overflow in the SSL-VPN daemon lets a remote

CVE-2023-27997Control plane, storage & DevOpsKnown exploitedFG-IR-23-097XORtigatecurated

Impact

A heap-based buffer overflow in the SSL-VPN daemon lets a remote, unauthenticated attacker run arbitrary code on the FortiGate — full device compromise. This is the 'XORtigate' bug, confirmed in CISA's KEV catalog as actively exploited; if this FortiGate is the VPN gateway into your cluster's management network, an attacker doesn't need any credentials to get a foothold there.

Who can reach it

Remote, unauthenticated — a specifically crafted request to the SSL-VPN service is sufficient, no login required.

What to do

Firmware upgrade of FortiOS/FortiProxy to the fixed release per Fortinet PSIRT FG-IR-23-097. Given confirmed active exploitation, patch immediately rather than waiting for a scheduled window, and assume compromise on any internet-facing unit that was unpatched during the exploitation window — a reboot alone doesn't remediate a box that was already popped.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.