---
id: CVE-2023-42790
title: >-
  A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through
  7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS
  6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0,
  FortiProxy 7.2.…
summary: >-
  A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through
  7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS
  6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0,
  FortiProxy 7.2.…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-121
vendor: fortinet
product: fortiproxy
affected:
  - 'fortiproxy >= 2.0.0, <= 2.0.13'
  - 'fortiproxy >= 7.0.0, <= 7.0.12'
  - 'fortiproxy >= 7.2.0, <= 7.2.6'
  - fortiproxy = 7.4.0
  - 'fortios >= 6.2.0, <= 6.2.15'
  - 'fortios >= 6.4.0, <= 6.4.14'
  - 'fortios >= 7.0.0, <= 7.0.12'
  - 'fortios >= 7.2.0, <= 7.2.5'
  - 'fortios >= 7.4.0, <= 7.4.1'
published: '2024-03-12'
updated: '2026-07-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-42790'
references:
  - url: 'https://fortiguard.com/psirt/FG-IR-23-328'
    label: psirt@fortinet.com
  - url: 'https://fortiguard.com/psirt/FG-IR-23-328'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01083
epssPercentile: 0.63701
ingestedAt: '2026-07-08T13:51:10.417Z'
---

## Overview

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12, FortiProxy 2.0.0 through 2.0.13, FortiSASE 23.2.b allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.

## Affected

- `fortiproxy >= 2.0.0, <= 2.0.13`
- `fortiproxy >= 7.0.0, <= 7.0.12`
- `fortiproxy >= 7.2.0, <= 7.2.6`
- `fortiproxy = 7.4.0`
- `fortios >= 6.2.0, <= 6.2.15`
- `fortios >= 6.4.0, <= 6.4.14`
- `fortios >= 7.0.0, <= 7.0.12`
- `fortios >= 7.2.0, <= 7.2.5`
- `fortios >= 7.4.0, <= 7.4.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
