CVE-2023-40716
published 2023-12-13CVE-2023-40716: An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiTester 2.3.0 through 7.2.3…
PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.0th percentile
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiTester 2.3.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments when running execute restore/backup .
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gv3p-qv63-g8qx: An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiTester 2
ghsa_unreviewed·2023-12-13
CVE-2023-40716 [MEDIUM] CWE-78 GHSA-gv3p-qv63-g8qx: An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiTester 2
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiTester 2.3.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments when running execute restore/backup .
Fortinet
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpr...
vendor_fortinet·2023-12-13·CVSS 6.7
CVE-2023-40716 [MEDIUM] CWE-78 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpr...
FG-IR-22-345: An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpr...
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiTester 2.3.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments when running execute restore/backup .
CVEs: CVE-2023-40716
CWEs: CWE-78
CVSS: 6.7 (medium)
Affected products: FortiTester
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-12-13
Published