CVE-2023-36547: OS Command Injection
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-36547?
CVE-2023-36547 is an improper neutralization of special elements used in an os command ( os command injection ) vulnerability in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4.
What is the severity of CVE-2023-36547?
The severity of CVE-2023-36547 is critical (9.8 out of 10).
How does CVE-2023-36547 work?
CVE-2023-36547 allows an attacker to execute unauthorized code or commands by exploiting a vulnerability in the Fortinet FortiWLM through specially crafted HTTP GET request parameters.
Which versions of Fortinet FortiWLM are affected by CVE-2023-36547?
CVE-2023-36547 affects Fortinet FortiWLM versions 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4.
How can I fix CVE-2023-36547?
To fix CVE-2023-36547, it is recommended to update Fortinet FortiWLM to a version that is not affected by the vulnerability.