CVE-2023-28000: OS Command Injection
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC CLI 7.1.0, 7.0.0 through 7.0.3, 6.2.0 through 6.2.4, 6.1 all versions, 6.0 all versions may allow a local and authenticated attacker to execute unauthorized commands via specifically crafted arguments in diagnose system df CLI command.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28000?
The severity of CVE-2023-28000 is high.
Which versions of FortiADC are affected by CVE-2023-28000?
FortiADC versions 6.0.0 through 6.0.4, 6.1.0 through 6.1.6, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, and 7.1.0 are affected by CVE-2023-28000.
How can an attacker exploit CVE-2023-28000?
A local and authenticated attacker can exploit CVE-2023-28000 by executing unauthorized commands using specially crafted arguments.
Is authentication required to exploit CVE-2023-28000?
Yes, authentication is required to exploit CVE-2023-28000.
Where can I find more information about CVE-2023-28000?
You can find more information about CVE-2023-28000 at the FortiGuard PSIRT website.