Record summary

CVE-2023-34993 has a selected CVSS score of 9.6 (critical); EIP currently links 1 Nuclei template.

Description

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 14, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 19, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected, unknown

CVE List, VulnCheck8.6.0 to ≤ 8.6.5affected
8.5.0 to ≤ 8.5.4affected

Nuclei templates

1
ProjectDiscoveryCRITICALFortinet FortiWLM Unauthenticated Command Injection VulnerabilityCVSS 9.8

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the affected system.

Impact

Unauthenticated attackers can exploit OS command injection to execute unauthorized commands on Fortinet FortiWLM systems, enabling complete system compromise and network infiltration.

Remediation

For FortiWLM version 8.6.0 through 8.6.5 upgrade to version >= 8.6.6. For FortiWLM version 8.5.0 through 8.5.4 upgrade to version >= 8.5.5.

WeaknessesCWE-78
Authorsdwisiswant0
Template tagscvecve2023fortinetfortiwlmrceunauthvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:fortinet:fortiwlm:*:*:*:*:*:*:*:*
Shodan: http.title:"FortiWLM"
Shodan: http.html:"fortiwlm"
Shodan: http.title:"fortiwlm"
FOFA: body="fortiwlm"
FOFA: title="fortiwlm"
Google: intitle:"fortiwlm"

Source: ProjectDiscovery

References

2