CVE-2023-42788: OS command injection
An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and version 6.2.0 through 6.2.11 may allow a local attacker with low privileges to execute unauthorized code via specifically crafted arguments to a CLI command
Other sources
An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow a local attacker with low privileges to execute unauthorized code via specifically crafted arguments to a CLI command
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2023-42788.
What is the severity level of CVE-2023-42788?
The severity level of CVE-2023-42788 is high (7.8).
Which software versions are affected by CVE-2023-42788?
FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12, and version 6.2.0 through 6.2.11 are affected by CVE-2023-42788.
What is the Common Weakness Enumeration (CWE) ID of CVE-2023-42788?
The Common Weakness Enumeration (CWE) ID of CVE-2023-42788 is CWE-78.
How can I find more information about CVE-2023-42788?
You can find more information about CVE-2023-42788 at the following link: [link](https://fortiguard.com/psirt/FG-IR-23-167).