cbcvebase.
CVE-2023-42788
published 2023-10-10

CVE-2023-42788: An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version…

PriorityP336medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
1.34%
68.1th percentile
An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and version 6.2.0 through 6.2.11 may allow a local attacker with low privileges to execute unauthorized code via specifically crafted arguments to a CLI command

Affected

12 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer
fortinetfortianalyzer6.2.0 – 6.2.11
fortinetfortianalyzer6.4.0 – 6.4.12
fortinetfortianalyzer7.0.0 – 7.0.8
fortinetfortianalyzer7.2.0 – 7.2.3
fortinetfortimanager
fortinetfortimanager
fortinetfortimanager6.2.0 – 6.2.11
fortinetfortimanager6.4.0 – 6.4.12
fortinetfortimanager7.0.0 – 7.0.8
fortinetfortimanager7.2.0 – 7.2.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.