CVE-2023-40716: OS Command Injection
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiTester 2.3.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments when running execute restore/backup .
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-40716?
CVE-2023-40716 is classified as a medium severity vulnerability that may allow authenticated attackers to execute unauthorized commands.
How do I fix CVE-2023-40716?
To fix CVE-2023-40716, update FortiTester to the latest version as recommended by Fortinet.
What systems are affected by CVE-2023-40716?
CVE-2023-40716 affects multiple versions of FortiTester, including versions from 2.3.0 to 7.2.3.
What type of vulnerability is CVE-2023-40716?
CVE-2023-40716 is categorized as an improper neutralization of special elements used in an OS command vulnerability.
Who can exploit CVE-2023-40716?
CVE-2023-40716 can be exploited by authenticated attackers who can craft specific arguments when executing restore or backup commands.