CVE-2023-34990: Path Traversal
Published Dec 18, 2024
·Updated
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.
Affected Software
3 affected components
Fortinet FortiWLM>=8.6.0<=8.6.5, >=8.5.0<=8.5.4
Fortinet FortiWLM>=8.5.0<8.5.5
Fortinet FortiWLM>=8.6.0<8.6.6
Remediation
Information
Please upgrade to FortiWLM version 8.6.6 or above
Please upgrade to FortiWLM version 8.5.5 or above
Event History
Dec 18, 2024
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
RemedyDescriptionSeverityWeakness
Dec 19, 2024
News Published
via BleepingComputer·05:24 PM
News Published
via BleepingComputer·05:26 PM
News Published
via Dark Reading·10:29 PM
Dec 20, 2024
News Published
via Dark Reading·12:01 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-34990?
CVE-2023-34990 is considered a critical vulnerability due to its potential to allow unauthorized code execution.
2
How do I fix CVE-2023-34990?
To mitigate CVE-2023-34990, upgrade Fortinet FortiWLM to version 8.6.6 or later, or 8.5.5 or later.
3
What versions are affected by CVE-2023-34990?
CVE-2023-34990 affects Fortinet FortiWLM versions 8.6.0 to 8.6.5 and 8.5.0 to 8.5.4.
4
What attack vector does CVE-2023-34990 exploit?
CVE-2023-34990 exploits a relative path traversal vulnerability that can lead to unauthorized code execution.
5
What are the potential impacts of CVE-2023-34990?
The impacts of CVE-2023-34990 include execution of unauthorized commands, which may compromise the security of the affected systems.