CVE-2023-26210: OS Command Injection
Multiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-78] in Fortinet FortiADCManager version 7.1.0 and before 7.0.0, FortiADC version 7.2.0 and before 7.1.2 allows a local authenticated attacker to execute arbitrary shell code as root user via crafted CLI requests.
Other sources
Multiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-78] vulnerability in Fortinet allows a local authenticated attacker to execute arbitrary shell code as root user via crafted CLI requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this Fortinet FortiADC vulnerability?
The vulnerability ID is CVE-2023-26210.
What is the severity level of CVE-2023-26210?
The severity level of CVE-2023-26210 is high with a CVSS score of 7.8.
Which software versions are affected by CVE-2023-26210?
Fortinet FortiADCManager version 7.1.0 and before 7.0.0, FortiADC version 7.2.0 and before 7.1.2 are affected by CVE-2023-26210.
What is the CWE ID associated with CVE-2023-26210?
The CWE ID associated with CVE-2023-26210 is CWE-78.
How can I fix the CVE-2023-26210 vulnerability?
To fix the CVE-2023-26210 vulnerability, it is recommended to update Fortinet FortiADCManager and FortiADC to versions that are not affected by the vulnerability.