CVE-2023-36642: OS Command Injection
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-36642.
What is the severity of CVE-2023-36642?
The severity of CVE-2023-36642 is high (7.8).
What is the affected software for CVE-2023-36642?
The affected software for CVE-2023-36642 is FortiTester version 3.0.0 through 7.2.3.
How does CVE-2023-36642 exploit work?
CVE-2023-36642 exploits an improper neutralization of special elements used in an OS command vulnerability in the management interface of FortiTester, allowing an authenticated attacker to execute unauthorized commands.
Is there a fix available for CVE-2023-36642?
Yes, it is recommended to upgrade FortiTester to a version beyond 7.2.3 as a fix for CVE-2023-36642.