CVE-2023-36553
published 2023-11-14CVE-2023-36553: A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and…
PriorityP272critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.88%
77.0th percentile
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 and 4.9.0 and 4.7.2 allows attacker to execute unauthorized code or commands via crafted API requests.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | 5.0.0 – 5.0.1 | — |
| fortinet | fortisiem | 5.1.0 – 5.1.3 | — |
| fortinet | fortisiem | 5.2.1 – 5.2.2 | — |
| fortinet | fortisiem | 5.2.5 – 5.2.8 | — |
| fortinet | fortisiem | 5.3.0 – 5.3.3 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts targeting the FortiSIEM report server via crafted API requests that inject OS commands (CVE-2023-36553, variant of CVE-2023-34992) ↗
- →Monitor for unauthenticated inbound API requests to FortiSIEM report server endpoints containing shell special characters or command separators, indicative of OS command injection attempts ↗
- →CVE-2023-36553 is a variant of CVE-2023-34992; detections and threat intelligence developed for CVE-2023-34992 should be reviewed and adapted for coverage of this related vulnerability ↗
- ·Affected FortiSIEM versions span a wide range (4.7.2 through 5.4.0); ensure version fingerprinting covers all listed sub-versions when scoping detection or asset inventory ↗
- ·The vulnerability is exploitable by remote, unauthenticated attackers, meaning no credential-based pre-filtering is effective as a detection gate; network-level visibility to the FortiSIEM report server API is required ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8m44-cmv2-wgmg: A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5
ghsa_unreviewed·2023-11-14
CVE-2023-36553 [CRITICAL] CWE-78 GHSA-8m44-cmv2-wgmg: A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 and 4.9.0 and 4.7.2 allows attacker to execute unauthorized code or commands via crafted API requests.
Fortinet
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM versi...
vendor_fortinet·2023-11-14·CVSS 9.8
CVE-2023-36553 [CRITICAL] CWE-78 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM versi...
FG-IR-23-135: A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM versi...
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 and 4.9.0 and 4.7.2 allows attacker to execute unauthorized code or commands via crafted API requests.
CVEs: CVE-2023-36553
CWEs: CWE-78
CVSS: 9.8 (critical)
Affected products: FortiSIEM, Fortinet
No detection rules found.
No public exploits indexed.
2023-11-14
Published