Description
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiTester version 7.3.0 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-40586 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-501 |
|
History
Wed, 25 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-09-25T17:33:50.277Z
Reserved: 2023-06-25T18:03:39.228Z
Link: CVE-2023-36642
Updated: 2024-08-02T16:52:54.250Z
Status : Modified
Published: 2023-09-13T13:15:09.127
Modified: 2024-11-21T08:10:09.817
Link: CVE-2023-36642
No data.
OpenCVE Enrichment
No data.
EUVD