CVE-2023-36634
published 2023-09-13CVE-2023-36634: An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through…
PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.52%
40.5th percentile
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbitrary files and directory via specially crafted command arguments.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiap | — | — |
| fortinet | fortiap-u | — | — |
| fortinet | fortiap-u | — | — |
| fortinet | fortiap-u | — | — |
| fortinet | fortiap-u | 5.4.0 – 5.4.6 | — |
| fortinet | fortiap-u | 5.4.3 – 5.4.6 | — |
| fortinet | fortiap-u | 6.0.0 – 6.0.4 | — |
| fortinet | fortiap-u | 6.2.0 – 6.2.5 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Arbitrary file listing and deletion through the CLI
vendor_fortinet·2023-09-13·CVSS 7.1
CVE-2023-36634 [HIGH] CWE-73 Arbitrary file listing and deletion through the CLI
FG-IR-23-123: Arbitrary file listing and deletion through the CLI
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbitrary files and directory via specially crafted command arguments.
CVEs: CVE-2023-36634
CWEs: CWE-73
CVSS: 7.1 (high)
Affected products: FortiAP, FortiAp-u
GHSA
GHSA-x6p5-565v-25pr: An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7
ghsa_unreviewed·2023-09-13
CVE-2023-36634 [HIGH] CWE-73 GHSA-x6p5-565v-25pr: An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbitrary files and directory via specially crafted command arguments.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-09-13
Published