CVE-2023-23777: OS Command Injection
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.18 and below may allow a privileged attacker to execute arbitrary bash commands via crafted cli backup parameters.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-23777.
What is the severity of CVE-2023-23777?
The severity of CVE-2023-23777 is high (severity value: 7).
Which software versions are affected by CVE-2023-23777?
FortiWeb version 7.0.0, 7.0.1, 6.4.0 to 6.4.3, and 6.3.6 to 6.3.18 are affected by CVE-2023-23777.
How does CVE-2023-23777 work?
CVE-2023-23777 is an OS Command Injection vulnerability which allows a privileged attacker to execute arbitrary bash commands via crafted cli backup parameters.
Where can I find more information about CVE-2023-23777?
You can find more information about CVE-2023-23777 on FortiGuard's website: https://fortiguard.com/psirt/FG-IR-22-131.