<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>CVE-2023-4863 - Heap overflow in Chrome/libwebp</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-23-381</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2025-01-14T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2025-01-14T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2025-01-14T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            Fortinet Product Security team has evaluated the impact of the vulnerablity affecting Google Chrome library listed below:CVE-2023-4863: severity HIGHHeap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.https://nvd.nist.gov/vuln/detail/CVE-2023-4863FortiClient and FortiClientEMS applications have embedded Chrome browser (for SAML authentication and administrative console application.)FortiSOAR is using Chrome to render reports on the backend.Libwepb is the library which renders &#34;.webp&#34; images into chrome browser.When a malicious image is displayed in chrome (with data overflow), program execution might be modified by the attacker. The attacker will need to escape google chrome sandboxing environment to perform additional damages.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Execute unauthorized code or commands
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiSOAR on-premise 7.6 all versions are not affectedFortiSOAR on-premise 7.5 all versions are not affectedFortiSOAR on-premise version 7.4.0FortiSOAR on-premise version 7.3.0 through 7.3.1FortiSOAR on-premise version 7.2.0 through 7.2.1FortiSOAR on-premise 7.0 all versionsFortiSOAR on-premise 6.4 all versionsFortiClientWindows 7.4 all versions are not affectedFortiClientWindows version 7.2.0 through 7.2.2FortiClientWindows version 7.0.0 through 7.0.10FortiClientWindows 6.4 all versionsFortiClientMac 7.4 all versions are not affectedFortiClientMac version 7.2.0 through 7.2.4FortiClientMac 7.0 all versionsFortiClientMac 6.4 all versionsFortiClientLinux 7.4 all versions are not affectedFortiClientLinux version 7.2.0 through 7.2.4FortiClientLinux 7.0 all versionsFortiClientLinux 6.4 all versionsFortiClientEMS 7.4 all versions are not affectedFortiClientEMS version 7.2.0 through 7.2.1FortiClientEMS version 7.0.0 through 7.0.10FortiClientEMS 6.4 all versions
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiClientWindows version 7.2.3 or abovePlease upgrade to FortiClientWindows version 7.0.10 or abovePlease upgrade to FortiClientLinux version 7.4.0 or abovePlease upgrade to FortiClientLinux version 7.2.5 or abovePlease upgrade to FortiClientMac version 7.4.0 or abovePlease upgrade to FortiClientMac version 7.2.5 or abovePlease upgrade to FortiClientEMS version 7.2.2 or abovePlease upgrade to FortiClientEMS version 7.0.10 or abovePlease upgrade to FortiSOAR version 7.4.1 Security Patch 3 or above Please upgrade to FortiSOAR version 7.3.2 Security Patch 4 or abovePlease upgrade to FortiSOAR version 7.2.2 Security Patch 9 or above
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:DocumentReferences>
        <cvrf:Reference>
            <cvrf:URL>https://fortiguard.fortinet.com/psirt/FG-IR-23-381</cvrf:URL>
            <cvrf:Description>CVE-2023-4863 - Heap overflow in Chrome/libwebp</cvrf:Description>
        </cvrf:Reference>
        <cvrf:Reference>
            <cvrf:URL>[1] https://nvd.nist.gov/vuln/detail/CVE-2023-4863</cvrf:URL>
            <cvrf:Description>[1] https://nvd.nist.gov/vuln/detail/CVE-2023-4863</cvrf:Description>
        </cvrf:Reference>
        <cvrf:Reference>
            <cvrf:URL>[2] https://www.wiz.io/blog/cve-2023-4863-and-cve-2023-5217-exploited-in-the-wild</cvrf:URL>
            <cvrf:Description>[2] https://www.wiz.io/blog/cve-2023-4863-and-cve-2023-5217-exploited-in-the-wild</cvrf:Description>
        </cvrf:Reference>
    </cvrf:DocumentReferences>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiClientEMS" Type="Product Name">
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-7.2.1">FortiClientEMS 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-7.2.0">FortiClientEMS 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-7.0.10">FortiClientEMS 7.0.10</FullProductName>
                </Branch>
                <Branch Name="7.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-7.0.9">FortiClientEMS 7.0.9</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-7.0.8">FortiClientEMS 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-7.0.7">FortiClientEMS 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-7.0.6">FortiClientEMS 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-7.0.5">FortiClientEMS 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-7.0.4">FortiClientEMS 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-7.0.3">FortiClientEMS 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-7.0.2">FortiClientEMS 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-7.0.1">FortiClientEMS 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-7.0.0">FortiClientEMS 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-6.4.9">FortiClientEMS 6.4.9</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-6.4.8">FortiClientEMS 6.4.8</FullProductName>
                </Branch>
                <Branch Name="6.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-6.4.7">FortiClientEMS 6.4.7</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-6.4.4">FortiClientEMS 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-6.4.3">FortiClientEMS 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-6.4.2">FortiClientEMS 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-6.4.1">FortiClientEMS 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientEMS-6.4.0">FortiClientEMS 6.4.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiClientLinux" Type="Product Name">
                <Branch Name="7.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.4">FortiClientLinux 7.2.4</FullProductName>
                </Branch>
                <Branch Name="7.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.3">FortiClientLinux 7.2.3</FullProductName>
                </Branch>
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.2">FortiClientLinux 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.1">FortiClientLinux 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.0">FortiClientLinux 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.13" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.13">FortiClientLinux 7.0.13</FullProductName>
                </Branch>
                <Branch Name="7.0.12" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.12">FortiClientLinux 7.0.12</FullProductName>
                </Branch>
                <Branch Name="7.0.11" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.11">FortiClientLinux 7.0.11</FullProductName>
                </Branch>
                <Branch Name="7.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.10">FortiClientLinux 7.0.10</FullProductName>
                </Branch>
                <Branch Name="7.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.9">FortiClientLinux 7.0.9</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.8">FortiClientLinux 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.7">FortiClientLinux 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.6">FortiClientLinux 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.5">FortiClientLinux 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.4">FortiClientLinux 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.3">FortiClientLinux 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.2">FortiClientLinux 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.1">FortiClientLinux 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.0">FortiClientLinux 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.9">FortiClientLinux 6.4.9</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.8">FortiClientLinux 6.4.8</FullProductName>
                </Branch>
                <Branch Name="6.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.7">FortiClientLinux 6.4.7</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.4">FortiClientLinux 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.3">FortiClientLinux 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.2">FortiClientLinux 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.1">FortiClientLinux 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.0">FortiClientLinux 6.4.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiClientMac" Type="Product Name">
                <Branch Name="7.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.2.4">FortiClientMac 7.2.4</FullProductName>
                </Branch>
                <Branch Name="7.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.2.3">FortiClientMac 7.2.3</FullProductName>
                </Branch>
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.2.2">FortiClientMac 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.2.1">FortiClientMac 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.2.0">FortiClientMac 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.14" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.14">FortiClientMac 7.0.14</FullProductName>
                </Branch>
                <Branch Name="7.0.13" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.13">FortiClientMac 7.0.13</FullProductName>
                </Branch>
                <Branch Name="7.0.12" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.12">FortiClientMac 7.0.12</FullProductName>
                </Branch>
                <Branch Name="7.0.11" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.11">FortiClientMac 7.0.11</FullProductName>
                </Branch>
                <Branch Name="7.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.10">FortiClientMac 7.0.10</FullProductName>
                </Branch>
                <Branch Name="7.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.9">FortiClientMac 7.0.9</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.8">FortiClientMac 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.7">FortiClientMac 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.6">FortiClientMac 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.5">FortiClientMac 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.4">FortiClientMac 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.3">FortiClientMac 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.2">FortiClientMac 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.1">FortiClientMac 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.0">FortiClientMac 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.10">FortiClientMac 6.4.10</FullProductName>
                </Branch>
                <Branch Name="6.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.9">FortiClientMac 6.4.9</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.8">FortiClientMac 6.4.8</FullProductName>
                </Branch>
                <Branch Name="6.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.7">FortiClientMac 6.4.7</FullProductName>
                </Branch>
                <Branch Name="6.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.6">FortiClientMac 6.4.6</FullProductName>
                </Branch>
                <Branch Name="6.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.5">FortiClientMac 6.4.5</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.4">FortiClientMac 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.3">FortiClientMac 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.2">FortiClientMac 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.1">FortiClientMac 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.0">FortiClientMac 6.4.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiClientWindows" Type="Product Name">
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.2.2">FortiClientWindows 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.2.1">FortiClientWindows 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.2.0">FortiClientWindows 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.10">FortiClientWindows 7.0.10</FullProductName>
                </Branch>
                <Branch Name="7.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.9">FortiClientWindows 7.0.9</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.8">FortiClientWindows 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.7">FortiClientWindows 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.6">FortiClientWindows 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.5">FortiClientWindows 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.4">FortiClientWindows 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.3">FortiClientWindows 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.2">FortiClientWindows 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.1">FortiClientWindows 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.0">FortiClientWindows 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.10">FortiClientWindows 6.4.10</FullProductName>
                </Branch>
                <Branch Name="6.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.9">FortiClientWindows 6.4.9</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.8">FortiClientWindows 6.4.8</FullProductName>
                </Branch>
                <Branch Name="6.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.7">FortiClientWindows 6.4.7</FullProductName>
                </Branch>
                <Branch Name="6.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.6">FortiClientWindows 6.4.6</FullProductName>
                </Branch>
                <Branch Name="6.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.5">FortiClientWindows 6.4.5</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.4">FortiClientWindows 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.3">FortiClientWindows 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.2">FortiClientWindows 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.1">FortiClientWindows 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.0">FortiClientWindows 6.4.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiSOAR on-premise" Type="Product Name">
                <Branch Name="7.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.4.0">FortiSOAR on-premise 7.4.0</FullProductName>
                </Branch>
                <Branch Name="7.3.1" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.3.1">FortiSOAR on-premise 7.3.1</FullProductName>
                </Branch>
                <Branch Name="7.3.0" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.3.0">FortiSOAR on-premise 7.3.0</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.2.1">FortiSOAR on-premise 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.2.0">FortiSOAR on-premise 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.0.3">FortiSOAR on-premise 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.0.2">FortiSOAR on-premise 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.0.1">FortiSOAR on-premise 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-7.0.0">FortiSOAR on-premise 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-6.4.4">FortiSOAR on-premise 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-6.4.3">FortiSOAR on-premise 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-6.4.1">FortiSOAR on-premise 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiSOAR on-premise-6.4.0">FortiSOAR on-premise 6.4.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>CVE-2023-4863 - Heap overflow in Chrome/libwebp</Title>
        <cvrf:CVE>CVE-2023-4863</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiClientEMS-7.2.1</ProductID>
                <ProductID>FortiClientEMS-7.2.0</ProductID>
                <ProductID>FortiClientEMS-7.0.10</ProductID>
                <ProductID>FortiClientEMS-7.0.9</ProductID>
                <ProductID>FortiClientEMS-7.0.8</ProductID>
                <ProductID>FortiClientEMS-7.0.7</ProductID>
                <ProductID>FortiClientEMS-7.0.6</ProductID>
                <ProductID>FortiClientEMS-7.0.5</ProductID>
                <ProductID>FortiClientEMS-7.0.4</ProductID>
                <ProductID>FortiClientEMS-7.0.3</ProductID>
                <ProductID>FortiClientEMS-7.0.2</ProductID>
                <ProductID>FortiClientEMS-7.0.1</ProductID>
                <ProductID>FortiClientEMS-7.0.0</ProductID>
                <ProductID>FortiClientEMS-6.4.9</ProductID>
                <ProductID>FortiClientEMS-6.4.8</ProductID>
                <ProductID>FortiClientEMS-6.4.7</ProductID>
                <ProductID>FortiClientEMS-6.4.4</ProductID>
                <ProductID>FortiClientEMS-6.4.3</ProductID>
                <ProductID>FortiClientEMS-6.4.2</ProductID>
                <ProductID>FortiClientEMS-6.4.1</ProductID>
                <ProductID>FortiClientEMS-6.4.0</ProductID>
                <ProductID>FortiClientLinux-7.2.4</ProductID>
                <ProductID>FortiClientLinux-7.2.3</ProductID>
                <ProductID>FortiClientLinux-7.2.2</ProductID>
                <ProductID>FortiClientLinux-7.2.1</ProductID>
                <ProductID>FortiClientLinux-7.2.0</ProductID>
                <ProductID>FortiClientLinux-7.0.13</ProductID>
                <ProductID>FortiClientLinux-7.0.12</ProductID>
                <ProductID>FortiClientLinux-7.0.11</ProductID>
                <ProductID>FortiClientLinux-7.0.10</ProductID>
                <ProductID>FortiClientLinux-7.0.9</ProductID>
                <ProductID>FortiClientLinux-7.0.8</ProductID>
                <ProductID>FortiClientLinux-7.0.7</ProductID>
                <ProductID>FortiClientLinux-7.0.6</ProductID>
                <ProductID>FortiClientLinux-7.0.5</ProductID>
                <ProductID>FortiClientLinux-7.0.4</ProductID>
                <ProductID>FortiClientLinux-7.0.3</ProductID>
                <ProductID>FortiClientLinux-7.0.2</ProductID>
                <ProductID>FortiClientLinux-7.0.1</ProductID>
                <ProductID>FortiClientLinux-7.0.0</ProductID>
                <ProductID>FortiClientLinux-6.4.9</ProductID>
                <ProductID>FortiClientLinux-6.4.8</ProductID>
                <ProductID>FortiClientLinux-6.4.7</ProductID>
                <ProductID>FortiClientLinux-6.4.4</ProductID>
                <ProductID>FortiClientLinux-6.4.3</ProductID>
                <ProductID>FortiClientLinux-6.4.2</ProductID>
                <ProductID>FortiClientLinux-6.4.1</ProductID>
                <ProductID>FortiClientLinux-6.4.0</ProductID>
                <ProductID>FortiClientMac-7.2.4</ProductID>
                <ProductID>FortiClientMac-7.2.3</ProductID>
                <ProductID>FortiClientMac-7.2.2</ProductID>
                <ProductID>FortiClientMac-7.2.1</ProductID>
                <ProductID>FortiClientMac-7.2.0</ProductID>
                <ProductID>FortiClientMac-7.0.14</ProductID>
                <ProductID>FortiClientMac-7.0.13</ProductID>
                <ProductID>FortiClientMac-7.0.12</ProductID>
                <ProductID>FortiClientMac-7.0.11</ProductID>
                <ProductID>FortiClientMac-7.0.10</ProductID>
                <ProductID>FortiClientMac-7.0.9</ProductID>
                <ProductID>FortiClientMac-7.0.8</ProductID>
                <ProductID>FortiClientMac-7.0.7</ProductID>
                <ProductID>FortiClientMac-7.0.6</ProductID>
                <ProductID>FortiClientMac-7.0.5</ProductID>
                <ProductID>FortiClientMac-7.0.4</ProductID>
                <ProductID>FortiClientMac-7.0.3</ProductID>
                <ProductID>FortiClientMac-7.0.2</ProductID>
                <ProductID>FortiClientMac-7.0.1</ProductID>
                <ProductID>FortiClientMac-7.0.0</ProductID>
                <ProductID>FortiClientMac-6.4.10</ProductID>
                <ProductID>FortiClientMac-6.4.9</ProductID>
                <ProductID>FortiClientMac-6.4.8</ProductID>
                <ProductID>FortiClientMac-6.4.7</ProductID>
                <ProductID>FortiClientMac-6.4.6</ProductID>
                <ProductID>FortiClientMac-6.4.5</ProductID>
                <ProductID>FortiClientMac-6.4.4</ProductID>
                <ProductID>FortiClientMac-6.4.3</ProductID>
                <ProductID>FortiClientMac-6.4.2</ProductID>
                <ProductID>FortiClientMac-6.4.1</ProductID>
                <ProductID>FortiClientMac-6.4.0</ProductID>
                <ProductID>FortiClientWindows-7.2.2</ProductID>
                <ProductID>FortiClientWindows-7.2.1</ProductID>
                <ProductID>FortiClientWindows-7.2.0</ProductID>
                <ProductID>FortiClientWindows-7.0.10</ProductID>
                <ProductID>FortiClientWindows-7.0.9</ProductID>
                <ProductID>FortiClientWindows-7.0.8</ProductID>
                <ProductID>FortiClientWindows-7.0.7</ProductID>
                <ProductID>FortiClientWindows-7.0.6</ProductID>
                <ProductID>FortiClientWindows-7.0.5</ProductID>
                <ProductID>FortiClientWindows-7.0.4</ProductID>
                <ProductID>FortiClientWindows-7.0.3</ProductID>
                <ProductID>FortiClientWindows-7.0.2</ProductID>
                <ProductID>FortiClientWindows-7.0.1</ProductID>
                <ProductID>FortiClientWindows-7.0.0</ProductID>
                <ProductID>FortiClientWindows-6.4.10</ProductID>
                <ProductID>FortiClientWindows-6.4.9</ProductID>
                <ProductID>FortiClientWindows-6.4.8</ProductID>
                <ProductID>FortiClientWindows-6.4.7</ProductID>
                <ProductID>FortiClientWindows-6.4.6</ProductID>
                <ProductID>FortiClientWindows-6.4.5</ProductID>
                <ProductID>FortiClientWindows-6.4.4</ProductID>
                <ProductID>FortiClientWindows-6.4.3</ProductID>
                <ProductID>FortiClientWindows-6.4.2</ProductID>
                <ProductID>FortiClientWindows-6.4.1</ProductID>
                <ProductID>FortiClientWindows-6.4.0</ProductID>
                <ProductID>FortiSOAR on-premise-7.4.0</ProductID>
                <ProductID>FortiSOAR on-premise-7.3.1</ProductID>
                <ProductID>FortiSOAR on-premise-7.3.0</ProductID>
                <ProductID>FortiSOAR on-premise-7.2.1</ProductID>
                <ProductID>FortiSOAR on-premise-7.2.0</ProductID>
                <ProductID>FortiSOAR on-premise-7.0.3</ProductID>
                <ProductID>FortiSOAR on-premise-7.0.2</ProductID>
                <ProductID>FortiSOAR on-premise-7.0.1</ProductID>
                <ProductID>FortiSOAR on-premise-7.0.0</ProductID>
                <ProductID>FortiSOAR on-premise-6.4.4</ProductID>
                <ProductID>FortiSOAR on-premise-6.4.3</ProductID>
                <ProductID>FortiSOAR on-premise-6.4.1</ProductID>
                <ProductID>FortiSOAR on-premise-6.4.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>7.1</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:X/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-23-381</URL>
                <Description>CVE-2023-4863 - Heap overflow in Chrome/libwebp</Description>
            </Reference>Reference>
            <Reference>
                <URL>[1] https://nvd.nist.gov/vuln/detail/CVE-2023-4863</URL>
                <Description>[1] https://nvd.nist.gov/vuln/detail/CVE-2023-4863</Description>
            </Reference>
            <Reference>
                <URL>[2] https://www.wiz.io/blog/cve-2023-4863-and-cve-2023-5217-exploited-in-the-wild</URL>
                <Description>[2] https://www.wiz.io/blog/cve-2023-4863-and-cve-2023-5217-exploited-in-the-wild</Description>
            </Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>