Vulnerability record · CVE-2023-27997 · published 13 June 2023
CVE-2023-27997: Fortinet FortiOS and FortiProxy SSL-VPN heap buffer overflow
Fortinet · Fortiproxy
FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow (CWE-122/CWE-787) reachable through specifically crafted requests. It is a pre-authentication, network-reachable flaw rated CVSS 9.8, and it is listed in CISA KEV with known ransomware campaign use, so it is a high-value target for edge-device compromise.
Description
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityPre-authentication remote code execution on internet-facing VPN appliances, listed in KEV with known ransomware use and very high EPSS.
What it is
FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow (CWE-122/CWE-787) reachable through specifically crafted requests. It is a pre-authentication, network-reachable flaw rated CVSS 9.8, and it is listed in CISA KEV with known ransomware campaign use, so it is a high-value target for edge-device compromise.
Impact
A remote attacker can execute arbitrary code or commands on the affected appliance, potentially gaining full control of the device and the network paths it protects.
Attack surface
Reachable over the network via the SSL-VPN interface; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to send the crafted requests.
Exploitation
Listed in CISA KEV since 2023-06-13 with known ransomware campaign use, and EPSS 30-day probability is 0.857 (99.7th percentile), indicating active and likely exploitation.
What to do
- Apply the Fortinet updates referenced in FG-IR-23-097 for FortiOS and FortiProxy as the first action.
- If immediate patching is not possible, disable or restrict SSL-VPN access to trusted sources and monitor for exploitation attempts.
- Rotate credentials and review VPN sessions on any device that may have been exposed before patching.
- Verify no unauthorized configuration changes, local accounts, or persistence mechanisms were added to edge devices.
- Track CISA KEV remediation due date (2023-07-04) and confirm closure.
Detection
- Inspect SSL-VPN request logs for malformed or oversized requests and anomalous URI patterns against the VPN endpoint.
- Monitor for unexpected process execution, new local accounts, or configuration changes on FortiOS/FortiProxy devices.
- Alert on outbound connections from VPN appliances to unfamiliar hosts, which may indicate post-exploitation activity.
- Correlate device logs with authentication events for logins from unusual geographies or at unusual times.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-27997 to the Known Exploited Vulnerabilities catalog on 13 June 2023 as "Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 4 July 2023.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-097 | Vendor Advisory |
| https://fortiguard.com/psirt/FG-IR-23-097 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27997 | US Government Resource |
Track CVE-2023-27997 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-27997), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.