Description
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbitrary files and directory via specially crafted command arguments.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiAP-U version 7.0.1 or above Please upgrade to FortiAP-U version 6.2.6 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-40578 | An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbitrary files and directory via specially crafted command arguments. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-123 |
|
History
Tue, 24 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-09-24T19:59:21.111Z
Reserved: 2023-06-25T18:03:39.226Z
Link: CVE-2023-36634
Updated: 2024-08-02T16:52:53.999Z
Status : Modified
Published: 2023-09-13T13:15:08.883
Modified: 2024-11-21T08:10:08.287
Link: CVE-2023-36634
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD