CVE-2023-27995: High severity fortinet fortisoar imap connector vulnerability
Published Apr 11, 2023
·Updated
A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
Affected Software
1 affected component
Fortinet FortiSOAR>=7.3.0<7.3.2
Remediation
Information
Please upgrade to FortiSOAR version 8.0.0 or above Please upgrade to FortiSOAR version 7.3.2 or above Please upgrade to FortiSOAR version 7.2.3 or above Please upgrade to FortiSOAR version 7.0.4 or above Please upgrade to FortiSOAR version 6.6.0 or above Please upgrade to FortiSOAR version 6.4.5 or above
Event History
Apr 11, 2023
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-27995.
2
What is the severity of CVE-2023-27995?
The severity of CVE-2023-27995 is high.
3
What software is affected by CVE-2023-27995?
Fortinet FortiSOAR versions 7.3.0 through 7.3.1 are affected by CVE-2023-27995.
4
How does CVE-2023-27995 impact the system?
CVE-2023-27995 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
5
How can I fix CVE-2023-27995?
To fix CVE-2023-27995, it is recommended to upgrade to Fortinet FortiSOAR version 7.3.2 or later.