First published: Thu Feb 16 2023(Updated: )
A double free in Fortinet FortiWeb version 7.0.0 through 7.0.3 may allows attacker to execute unauthorized code or commands via specially crafted commands
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWeb | >=7.0.0<=7.0.3 |
Please upgrade to FortiWeb version 7.2.0 or above Please upgrade to FortiWeb version 7.0.4 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-40683.
The severity of CVE-2022-40683 is high.
Fortinet FortiWeb versions 7.0.0 through 7.0.3 are affected by CVE-2022-40683.
An attacker can exploit CVE-2022-40683 by executing unauthorized code or commands via specially crafted commands.
Please refer to the official Fortinet FortiWeb advisories for the fix of CVE-2022-40683.