CVE-2023-27999: OS Command Injection
Published May 3, 2023
·Updated
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 through 7.1.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
Affected Software
2 affected components
Fortinet FortiADC>=7.1.0<7.1.2
Fortinet FortiADC=7.2.0
Remediation
Information
Please upgrade to FortiADC version 7.2.1 or above Please upgrade to FortiADC version 7.1.2 or above
Event History
May 3, 2023
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-27999.
2
What is the severity of CVE-2023-27999?
The severity of CVE-2023-27999 is high.
3
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-78.
4
Which versions of FortiADC are affected?
FortiADC versions 7.1.0 through 7.1.1 and 7.2.0 are affected.
5
How can an attacker exploit this vulnerability?
An authenticated attacker may execute unauthorized commands via crafted arguments to existing commands.