---
id: CVE-2023-42789
title: >-
  A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1,
  FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0
  through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy
  7.2.0 throug…
summary: >-
  A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1,
  FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0
  through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy
  7.2.0 throug…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: fortinet
product: fortiproxy
affected:
  - 'fortiproxy >= 2.0.0, <= 2.0.13'
  - 'fortiproxy >= 7.0.0, <= 7.0.12'
  - 'fortiproxy >= 7.2.0, <= 7.2.6'
  - fortiproxy = 7.4.0
  - 'fortios >= 6.2.0, <= 6.2.15'
  - 'fortios >= 6.4.0, <= 6.4.14'
  - 'fortios >= 7.0.0, <= 7.0.12'
  - 'fortios >= 7.2.0, <= 7.2.5'
  - fortios = 7.4.0
  - fortios = 7.4.1
published: '2024-03-12'
updated: '2026-07-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-42789'
references:
  - url: 'https://fortiguard.com/psirt/FG-IR-23-328'
    label: psirt@fortinet.com
  - url: 'https://fortiguard.com/psirt/FG-IR-23-328'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.03306
epssPercentile: 0.88057
ingestedAt: '2026-07-08T13:51:10.411Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/jhonnybonny/CVE-2023-42789'
  checkedAt: '2026-09-25T08:20:42.566Z'
exploitAvailable: true
---

## Overview

A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12, FortiProxy 2.0.0 through 2.0.13, FortiSASE 23.2.b allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.

## Affected

- `fortiproxy >= 2.0.0, <= 2.0.13`
- `fortiproxy >= 7.0.0, <= 7.0.12`
- `fortiproxy >= 7.2.0, <= 7.2.6`
- `fortiproxy = 7.4.0`
- `fortios >= 6.2.0, <= 6.2.15`
- `fortios >= 6.4.0, <= 6.4.14`
- `fortios >= 7.0.0, <= 7.0.12`
- `fortios >= 7.2.0, <= 7.2.5`
- `fortios = 7.4.0`
- `fortios = 7.4.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
