← Vulnerability feed

Vulnerability record · CVE-2023-27997 · published 13 June 2023

CVE-2023-27997: Fortinet FortiOS and FortiProxy SSL-VPN heap buffer overflow

Fortinet · Fortiproxy

FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow (CWE-122/CWE-787) reachable through specifically crafted requests. It is a pre-authentication, network-reachable flaw rated CVSS 9.8, and it is listed in CISA KEV with known ransomware campaign use, so it is a high-value target for edge-device compromise.

9.8 CVSS 3.1 Critical CISA KEV since 13 Jun 2023 Known ransomware use EPSS 86% · top 0.3% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score
86%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
31 Jul 2026Last modified by NVD

Description

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityPre-authentication remote code execution on internet-facing VPN appliances, listed in KEV with known ransomware use and very high EPSS.

What it is

FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow (CWE-122/CWE-787) reachable through specifically crafted requests. It is a pre-authentication, network-reachable flaw rated CVSS 9.8, and it is listed in CISA KEV with known ransomware campaign use, so it is a high-value target for edge-device compromise.

Impact

A remote attacker can execute arbitrary code or commands on the affected appliance, potentially gaining full control of the device and the network paths it protects.

Attack surface

Reachable over the network via the SSL-VPN interface; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to send the crafted requests.

Exploitation

Listed in CISA KEV since 2023-06-13 with known ransomware campaign use, and EPSS 30-day probability is 0.857 (99.7th percentile), indicating active and likely exploitation.

What to do

  • Apply the Fortinet updates referenced in FG-IR-23-097 for FortiOS and FortiProxy as the first action.
  • If immediate patching is not possible, disable or restrict SSL-VPN access to trusted sources and monitor for exploitation attempts.
  • Rotate credentials and review VPN sessions on any device that may have been exposed before patching.
  • Verify no unauthorized configuration changes, local accounts, or persistence mechanisms were added to edge devices.
  • Track CISA KEV remediation due date (2023-07-04) and confirm closure.

Detection

  • Inspect SSL-VPN request logs for malformed or oversized requests and anomalous URI patterns against the VPN endpoint.
  • Monitor for unexpected process execution, new local accounts, or configuration changes on FortiOS/FortiProxy devices.
  • Alert on outbound connections from VPN appliances to unfamiliar hosts, which may indicate post-exploitation activity.
  • Correlate device logs with authentication events for logins from unusual geographies or at unusual times.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-27997 to the Known Exploited Vulnerabilities catalog on 13 June 2023 as "Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 4 July 2023.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-27997 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24858Fortinet FortiCloud SSO authentication bypass across registered devicesA CWE-288 authentication bypass in Fortinet FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy and FortiWeb lets an attacker with a FortiCl…KEVEPSS 86%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed9.8CVE-2025-59718Fortinet FortiOS/FortiProxy SAML signature check bypass in FortiCloud SSOFortiOS, FortiProxy and FortiSwitchManager fail to properly verify the cryptographic signature of SAML responses used for FortiCloud SSO login. An un…KEVEPSS 68%analysed9.8CVE-2024-55591FortiOS and FortiProxy authentication bypass via Node.js websocketFortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 contain an authentication bypass (CWE-288) reachable throug…KEVEPSS 94%analysed9.8CVE-2024-23113Fortinet FortiOS and related products format string remote code executionA use of externally-controlled format string (CWE-134) in Fortinet FortiOS, FortiProxy, FortiPAM and FortiSwitchManager lets an attacker execute unau…KEVEPSS 62%analysed9.8CVE-2024-21762Fortinet FortiOS and FortiProxy out-of-bounds write in SSL VPNFortiOS and FortiProxy contain an out-of-bounds write (CWE-787) reachable through specifically crafted requests. The flaw affects a wide range of For…KEVEPSS 83%analysed9.8CVE-2022-42475FortiOS and FortiProxy SSL-VPN heap buffer overflow allows remote code executionA heap-based buffer overflow (CWE-122/CWE-787) in the FortiOS and FortiProxy SSL-VPN component lets a remote attacker trigger memory corruption throu…KEVEPSS 99%analysed9.8CVE-2022-40684Fortinet FortiOS, FortiProxy and FortiSwitchManager admin interface auth bypassAn authentication bypass (CWE-288, alternate path or channel) in Fortinet FortiOS 7.2.0-7.2.1 and 7.0.0-7.0.6, FortiProxy 7.2.0 and 7.0.0-7.0.6, and …KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2023-27997), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.