CVE-2023-41838: OS Command Injection
An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-41838?
CVE-2023-41838 is an improper neutralization of special elements used in an os command ('os command injection') vulnerability in FortiManager 7.4.0 and 7.2.0 through 7.2.3 that may allow an attacker to execute unauthorized code or commands via FortiManager cli.
How does CVE-2023-41838 affect FortiAnalyzer?
FortiAnalyzer versions 6.2.0 to 6.2.11, 6.4.0 to 6.4.12, 7.0.0 to 7.0.8, and 7.2.0 to 7.2.3 are affected by CVE-2023-41838.
How does CVE-2023-41838 affect FortiManager?
FortiManager versions 6.2.0 to 6.2.11, 6.4.0 to 6.4.12, 7.0.0 to 7.0.8, and 7.2.0 to 7.2.3 are affected by CVE-2023-41838.
What is the severity of CVE-2023-41838?
CVE-2023-41838 has a severity score of 7.1, which is classified as high.
How can I mitigate CVE-2023-41838?
Upgrade FortiManager to a version that is not affected by CVE-2023-41838, as recommended by FortiGuard advisory FG-IR-23-169.