CVE-2023-41842: Format string vulnerability in administrative interface
A use of externally-controlled format string vulnerability [CWE-134] in FortiManager, FortiAnalyzer, FortiAnalyzer-BigData & FortiPortal may allow a privileged attacker to execute unauthorized code or commands via specially crafted command arguments.
Other sources
A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41842?
CVE-2023-41842 has been classified as a critical vulnerability due to its potential to allow privileged attackers to execute unauthorized code.
How do I fix CVE-2023-41842?
To fix CVE-2023-41842, update your FortiManager, FortiAnalyzer, or FortiPortal to the latest patched version as specified by Fortinet.
Which products are affected by CVE-2023-41842?
CVE-2023-41842 affects FortiManager, FortiAnalyzer, and FortiPortal across various versions.
Can CVE-2023-41842 be exploited remotely?
Yes, CVE-2023-41842 can be exploited remotely by an attacker leveraging specially crafted command arguments.
What type of vulnerability is CVE-2023-41842?
CVE-2023-41842 is categorized as a use of externally-controlled format string vulnerability, which can lead to code execution.