CVE-2023-29184: SSH key is added even if operation is aborted
An incomplete cleanup vulnerability [CWE-459] in FortiOS & FortiProxy may allow a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.
Other sources
An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29184?
CVE-2023-29184 has a high severity level due to its potential impact on system integrity from incomplete cleanup vulnerabilities.
How do I fix CVE-2023-29184?
To remediate CVE-2023-29184, update FortiOS to version 7.2.3 or above and FortiProxy to version 7.0.9 or above.
What types of systems are affected by CVE-2023-29184?
CVE-2023-29184 affects FortiOS versions 7.2 and earlier, and specific versions of FortiProxy.
Who can exploit CVE-2023-29184?
CVE-2023-29184 can be exploited by a VDOM privileged attacker using crafted CLI requests.
What is the impact of CVE-2023-29184 on FortiOS and FortiProxy?
The impact of CVE-2023-29184 includes unauthorized addition of SSH key files on the system, potentially compromising security.