CVE-2023-34993
Fortinet fortiwlm Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2023-34993 has a selected CVSS score of 9.6 (critical); EIP currently links 1 Nuclei template.
Description
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 14, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 19, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FortiWLMBrowse Fortinet / FortiWLMDefault status: unaffected, unknown | CVE List, VulnCheck | 8.6.0 to ≤ 8.6.5 | affected |
| 8.5.0 to ≤ 8.5.4 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALFortinet FortiWLM Unauthenticated Command Injection VulnerabilityCVSS 9.8
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the affected system.
Impact
Unauthenticated attackers can exploit OS command injection to execute unauthorized commands on Fortinet FortiWLM systems, enabling complete system compromise and network infiltration.
Remediation
For FortiWLM version 8.6.0 through 8.6.5 upgrade to version >= 8.6.6. For FortiWLM version 8.5.0 through 8.5.4 upgrade to version >= 8.5.5.
Source: ProjectDiscovery