CVE detail
CVE-2023-33308 — CVE-2023-33308
Published 2023-07-26 · Modified 2026-06-17 · Vendor fortinet · Product fortiproxy · Source nvd
CRITICAL
severity
CVSS-derived band
0.0212
EPSS probability
exploitation probability, 30d
80.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted packets reaching proxy policies or firewall policies with proxy mode alongside deep or full packet inspection.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References