CVE-2023-36549: OS Command Injection
Published Oct 10, 2023
·Updated
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
Affected Software
2 affected components
Fortinet FortiWLM>=8.5.0<=8.5.4
Fortinet FortiWLM>=8.6.0<=8.6.5
Remediation
Information
Please upgrade to FortiWLM version 8.6.6 or above
Please upgrade to FortiWLM version 8.5.5 or above
Event History
Oct 10, 2023
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-36549.
2
What is the severity of CVE-2023-36549?
The severity of CVE-2023-36549 is critical (9.8 out of 10).
3
What is the affected software?
The affected software is Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4.
4
How can an attacker exploit CVE-2023-36549?
An attacker can exploit CVE-2023-36549 by executing unauthorized code or commands via specifically crafted HTTP GET request parameters.
5
Is there a fix available for CVE-2023-36549?
Yes, it is recommended to update to the latest version of Fortinet FortiWLM to fix CVE-2023-36549.