Fortinet patched multiple vulnerabilities in FortiOS and FortiProxy, led by critical captive-portal flaws CVE-2023-42789 (out-of-bounds write) and CVE-2023-42790 (stack-based buffer overflow). Devices with captive portal enabled could be exposed to arbitrary code or command execution through specially crafted HTTP requests; Fortinet rated the flaws CVSS 9.3 and reported no known exploitation when the advisory was issued. The updates also address CVE-2024-23112, an SSL VPN web-mode bookmark authorization bypass that lets an authenticated user manipulate a URL to access another user's bookmark, and CVE-2023-46717, which can elevate a read-only user's privileges to read-write where FortiAuthenticator is deployed in high-availability mode.
Organizations should upgrade affected FortiOS and FortiProxy installations to Fortinet's fixed releases promptly, prioritizing internet-facing systems and appliances using captive portals. Until patching is complete, Fortinet recommends disabling form-based authentication schemes to mitigate the captive-portal RCE flaws, disabling SSL VPN web mode to mitigate bookmark exposure, and disabling FortiToken Mobile push notifications in FortiAuthenticator RADIUS policies for affected HA deployments. FortiSASE 23.3.b already includes fixes for the two captive-portal vulnerabilities.

Map this exposure pattern across your cloud, code, and identities.
4 events from the most recent confirmed update back to the earliest known activity.
Fortinet corrected the affected-version information in its advisory for the FortiAuthenticator HA improper-authentication vulnerability.
Fortinet published an advisory for CVE-2024-23112, a CWE-639 user-controlled-key vulnerability in FortiOS and FortiProxy SSL VPN bookmarks. An authenticated attacker could manipulate a URL to access another user's bookmark; Fortinet supplied fixed releases and advised disabling SSL VPN web mode as a workaround.
Fortinet published an advisory for CVE-2023-42789 and CVE-2023-42790, an out-of-bounds write and stack-based buffer overflow in FortiOS and FortiProxy captive portal functionality. The critical flaws could permit unauthenticated arbitrary code or command execution through crafted HTTP requests on devices with captive portal enabled; Fortinet issued fixed versions, a configuration workaround, and a virtual patch signature.
Fortinet published an advisory for CVE-2023-46717, an improper-authentication vulnerability affecting FortiOS deployments using FortiAuthenticator in high-availability mode. An authenticated user with read-only permissions could obtain read-write access through successive login attempts; fixed FortiOS releases and a push-notification workaround were provided.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
4 references tracked. Mallory keeps watching after this page renders.
fortiguard.fortinet.com
Open sourcefortiguard.fortinet.com
Open sourcefortiguard.fortinet.com
Open sourcencsc.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.