CVE-2023-34985: OS Command Injection
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Fortinet FortiWLM vulnerability?
The vulnerability ID for this Fortinet FortiWLM vulnerability is CVE-2023-34985.
What is the severity of CVE-2023-34985?
The severity of CVE-2023-34985 is high with a CVSS score of 8.8.
What software versions are affected by CVE-2023-34985?
Fortinet FortiWLM versions 8.6.0 through 8.6.5 and versions 8.5.0 through 8.5.4 are affected by CVE-2023-34985.
What is the impact of CVE-2023-34985?
CVE-2023-34985 allows an attacker to execute unauthorized code or commands via specifically crafted HTTP GET request parameters.
Is there a fix available for CVE-2023-34985?
To fix CVE-2023-34985, Fortinet FortiWLM users should update to a version that is not affected by the vulnerability.