---
id: CVE-2023-27997
title: >-
  A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4
  and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16
  and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below,
  versio…
summary: >-
  A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4
  and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16
  and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below,
  versio…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-122
  - CWE-787
vendor: fortinet
product: fortiproxy
affected:
  - 'fortiproxy >= 1.1.0, <= 1.1.6'
  - 'fortiproxy >= 1.2.0, <= 1.2.13'
  - 'fortiproxy >= 2.0.0, <= 2.0.12'
  - 'fortiproxy >= 7.0.0, <= 7.0.9'
  - 'fortiproxy >= 7.2.0, <= 7.2.3'
  - 'fortios >= 6.0.0, <= 6.0.16'
  - 'fortios >= 6.2.0, <= 6.2.13'
  - 'fortios >= 6.4.0, <= 6.4.12'
  - 'fortios >= 7.0.0, <= 7.0.11'
  - 'fortios >= 7.2.0, <= 7.2.4'
  - 'fortios >= 6.0.12, <= 6.0.16'
  - 'fortios >= 6.2.9, <= 6.2.13'
  - fortios = 6.0.10
  - fortios = 6.2.4
  - fortios = 6.2.6
  - fortios = 6.2.7
  - fortios = 6.4.2
  - fortios = 6.4.6
  - fortios = 6.4.8
  - fortios = 6.4.10
  - fortios = 6.4.12
  - fortios = 7.0.5
  - fortios = 7.0.10
published: '2023-06-13'
updated: '2026-07-31'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-27997'
references:
  - url: 'https://fortiguard.com/psirt/FG-IR-23-097'
    label: psirt@fortinet.com
  - url: 'https://fortiguard.com/psirt/FG-IR-23-097'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27997
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.85689
epssPercentile: 0.99715
kev: true
kevDateAdded: '2023-06-13'
kevDueDate: '2023-07-04'
kevRansomware: true
exploited: true
zeroDay: true
ingestedAt: '2026-07-31T04:58:34.391Z'
exploits:
  github: 12
  githubRepos:
    - 'https://github.com/rio128128/CVE-2023-27997-POC'
    - 'https://github.com/BishopFox/CVE-2023-27997-check'
    - 'https://github.com/imbas007/CVE-2023-27997-Check'
  checkedAt: '2026-09-23T07:13:25.097Z'
exploitAvailable: true
---

## Overview

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.

## Affected

- `fortiproxy >= 1.1.0, <= 1.1.6`
- `fortiproxy >= 1.2.0, <= 1.2.13`
- `fortiproxy >= 2.0.0, <= 2.0.12`
- `fortiproxy >= 7.0.0, <= 7.0.9`
- `fortiproxy >= 7.2.0, <= 7.2.3`
- `fortios >= 6.0.0, <= 6.0.16`
- `fortios >= 6.2.0, <= 6.2.13`
- `fortios >= 6.4.0, <= 6.4.12`
- `fortios >= 7.0.0, <= 7.0.11`
- `fortios >= 7.2.0, <= 7.2.4`
- `fortios >= 6.0.12, <= 6.0.16`
- `fortios >= 6.2.9, <= 6.2.13`
- `fortios = 6.0.10`
- `fortios = 6.2.4`
- `fortios = 6.2.6`
- `fortios = 6.2.7`
- `fortios = 6.4.2`
- `fortios = 6.4.6`
- `fortios = 6.4.8`
- `fortios = 6.4.10`
- `fortios = 6.4.12`
- `fortios = 7.0.5`
- `fortios = 7.0.10`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
