CVE-2023-27997, also known as XORtigate, is a heap-based buffer overflow in the SSL-VPN component of FortiOS, FortiOS-6K7K, and FortiProxy. Specially crafted requests can trigger memory corruption in the SSL-VPN service, allowing an unauthenticated remote attacker to execute arbitrary code or commands. Affected releases include FortiOS 7.2.4 and earlier, 7.0.11 and earlier, 6.4.12 and earlier, and 6.0.16 and earlier; and FortiProxy 7.2.3 and earlier, 7.0.9 and earlier, 2.0.12 and earlier, and all 1.2 and 1.1 releases.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (6 hidden).
This is a 100-file exploit catalog rather than a detection-only repository: the supplied structure contains README.md, .gitignore, and 98 standalone Python clients in exp/. Filenames encode a FortiGate appliance SKU and exact FortiOS build, spanning models such as 30E through 3000D and firmware trains from 6.0 through 7.4. The critical asset is the per-image offset/gadget matrix: every client hardcodes build-specific stack layouts, BSS/GOT/function addresses, ROP gadgets, object sizes, and spray parameters. The code implements two unauthenticated SSL-VPN RCE families identified in the README as CVE-2024-21762 and CVE-2023-27997. CVE-2024-21762-style clients issue malformed chunked POST requests to /aaaa/bbbb while spraying /remote/error or /remote/hostcheck_validate. They corrupt request-processing state, redirect control flow through per-build ROP chains, and invoke FortiGate's internal execute_cmd routine. CVE-2023-27997-style clients first obtain a dynamic salt from /remote/info, reproduce the MD5/XOR enc= encoding, calculate seeds for controlled byte writes, spray SSL-related objects, and overwrite an indirect target/GOT entry to execute attacker-controlled commands. Payload delivery has three observed forms: direct Node.js HTTP retrieval and eval of a configurable /s.js URL; TFTP retrieval of s.js into /tmp/s followed by Node execution; and x86-64/ARM raw-payload stagers. The latter obtain a length-prefixed second stage from a configurable TCP service, allocate executable memory, execute the received bytes, and make a second configurable TCP callback that functions as a reverse shell channel. TLS certificate verification is disabled throughout. Many clients repeatedly attack in parallel, with hardcoded CPU/thread counts and high connection/spray volumes, indicating reliability tuning rather than a minimal PoC. No fixed victim IP, domain, or attacker infrastructure is embedded. Target and callback hosts/ports are command-line supplied, so the fingerprintable observables are primarily the SSL-VPN paths, malformed chunked-transfer patterns, unusually large form/hostcheck requests, the FortiSSLVPN user agent, requests to /remote/info, and outbound target traffic to operator-selected HTTP, TFTP, or raw TCP services. README references additional launcher, listener, shellcode, and JavaScript files, but those are not present in the supplied file listing; conclusions about their contents are therefore limited to the README's description.
This repository provides a Python proof-of-concept exploit for CVE-2023-27997, a critical heap-based buffer overflow vulnerability in Fortinet FortiGate SSL-VPN (FortiOS) devices. The exploit consists of a single main script ('fgt-cve-2023-27997-exploit.py'), a README.md with detailed usage and technical background, and a requirements.txt listing dependencies (requests, urllib3, numpy, scipy). The exploit works by first retrieving a 'salt' value from the target's '/remote/info' endpoint, then crafting a ROP chain payload (demonstrated with a ping command), encrypting it, and sending it to the vulnerable '/remote/hostcheck_validate' endpoint as the 'enc' parameter. The script is designed for authorized testing and demonstrates remote code execution (RCE) without authentication. The README provides affected version ranges for FortiOS and FortiProxy, usage instructions, and technical details about the vulnerability and exploit chain. The attack vector is network-based, targeting the SSL-VPN web interface. The exploit is a PoC and requires the attacker to specify the target IP and port.
This repository contains a proof-of-concept (POC) exploit for CVE-2023-27997, a critical remote code execution vulnerability in Fortinet FortiGate SSL VPN devices. The main file, 'exploit.py', is a heavily commented Python script that demonstrates the exploitation process, including buffer overflow and ROP chain construction, but does not provide a fully weaponized payload. The exploit requires the attacker to specify the target (host:port) and a local callback address. It uses custom SSL/TLS connections and crafts HTTP(S) requests to the '/remote/error' endpoint on the target device. The script is intended for educational purposes and does not include fingerprinting or vulnerability checks. The README.md provides a brief overview and points to a detailed blog post for further information. The exploit demonstrates the attack vector and methodology but is not directly usable for real-world attacks without further development.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Fortinet FortiGate vulnerability probed during the actor's fingerprinting and reconnaissance of 3BB's FortiGate SSL-VPN endpoint.
A pre-authentication heap-overflow vulnerability in FortiOS SSL-VPN, known as XORtigate, that was probed during reconnaissance of the 3BB FortiGate endpoint.
An exploited FortiOS SSL-VPN vulnerability referenced as one of the flaws bypassed by CVE-2025-68686.
A FortiGate SSL-VPN vulnerability used by the MexicanMafia/PanchoVilla threat actor for initial access in Operation Escaneo.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.