CVE-2023-34993: OS Command Injection
Published Oct 10, 2023
·Updated
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
Affected Software
2 affected components
Fortinet FortiWLM>=8.5.0<=8.5.4
Fortinet FortiWLM>=8.6.0<=8.6.5
Remediation
Information
Please upgrade to FortiWLM version 8.6.6 or above Please upgrade to FortiWLM version 8.5.5 or above
Event History
Oct 10, 2023
CVE Published
via MITRE·04:51 PM
Data Sourced
via MITRE·04:51 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Fortinet FortiWLM vulnerability?
The vulnerability ID for this Fortinet FortiWLM vulnerability is CVE-2023-34993.
2
What is the severity of CVE-2023-34993?
The severity of CVE-2023-34993 is critical.
3
What software versions are affected by CVE-2023-34993?
Fortinet FortiWLM versions 8.5.0 through 8.5.4 and 8.6.0 through 8.6.5 are affected by CVE-2023-34993.
4
How can an attacker exploit CVE-2023-34993?
An attacker can exploit CVE-2023-34993 by sending a specifically crafted HTTP GET request with malicious parameters.
5
Is there a fix for CVE-2023-34993?
Yes, the vendor has released fixes for this vulnerability. Please refer to the vendor's security advisory for more details.