CVE-2023-27993: Path Traversal
Published May 3, 2023
·Updated
A relative path traversal [CWE-23] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a privileged attacker to delete arbitrary directories from the underlying file system via crafted CLI commands.
Affected Software
3 affected components
Fortinet FortiADC>=5.2.0<=7.0.5
Fortinet FortiADC>=7.1.0<7.1.2
Fortinet FortiADC=7.2.0
Remediation
Information
Please upgrade to FortiADC version 7.2.1 or above Please upgrade to FortiADC version 7.1.2 or above
Event History
May 3, 2023
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
10:15 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-27993.
2
What is the severity of CVE-2023-27993?
The severity of CVE-2023-27993 is high (7.1).
3
Which software versions are affected by CVE-2023-27993?
Fortinet FortiADC versions 7.2.0 and before 7.1.1 are affected by CVE-2023-27993.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-23.
5
How can an attacker exploit CVE-2023-27993?
An attacker can exploit CVE-2023-27993 by using crafted CLI commands to perform a relative path traversal and delete arbitrary directories from the underlying file system.