CVE-2023-23783: High severity fortinet fortiweb vulnerability
Published Feb 16, 2023
·Updated
A use of externally-controlled format string in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb 6.4 all versions allows attacker to execute unauthorized code or commands via specially crafted command arguments.
Affected Software
2 affected components
Fortinet FortiWeb>=6.4.0<6.4.2
Fortinet FortiWeb>=7.0.0<7.0.2
Remediation
Information
Please upgrade to FortiWeb version 7.0.2 or above
Event History
Feb 16, 2023
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-23783.
2
What is the severity of CVE-2023-23783?
The severity of CVE-2023-23783 is high, with a severity value of 7.8.
3
Which versions of Fortinet FortiWeb are affected by CVE-2023-23783?
Fortinet FortiWeb version 7.0.0 through 7.0.1, and all versions of FortiWeb 6.4 up to 6.4.2 are affected by CVE-2023-23783.
4
What is the impact of CVE-2023-23783?
CVE-2023-23783 allows an attacker to execute unauthorized code or commands via specially crafted command arguments.
5
Is there a fix available for CVE-2023-23783?
A fix is available for CVE-2023-23783, and users are advised to update to the latest version of Fortinet FortiWeb.