CVE-2023-42784: Web application firewall rules bypass by using an empty filename
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.
Other sources
Two improper handling of syntactically invalid structure vulnerabilities [CWE-228] in FortiWeb may allow an unauthenticated attacker to bypass web firewall protections via HTTP/S crafted requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-42784?
CVE-2023-42784 has been classified as a critical vulnerability due to its potential to allow unauthorized remote code execution.
How do I fix CVE-2023-42784?
To fix CVE-2023-42784, upgrade Fortinet FortiWeb to a version later than 7.4.6, 7.2.10, or 7.0.10.
Who is affected by CVE-2023-42784?
CVE-2023-42784 affects Fortinet FortiWeb versions 7.0.0 to 7.0.10, 7.2.0 to 7.2.10, and 7.4.0 to 7.4.6.
What types of attacks can exploit CVE-2023-42784?
CVE-2023-42784 can be exploited through specially crafted HTTP/S requests, potentially allowing attackers to execute unauthorized commands.
Is there a workaround for CVE-2023-42784?
There are no recommended workarounds for CVE-2023-42784; the only mitigation is to apply the available software updates.