First published: Tue Oct 10 2023(Updated: )
A relative path traversal [CWE-23] vulnerability in FortiManager and FortiAnalyzer may allow a remote attacker with low privileges to execute unauthorized code via crafted HTTP requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiManager | >=6.2.0<6.2.12 | |
Fortinet FortiManager | >=6.4.0<6.4.13 | |
Fortinet FortiManager | >=7.0.0<7.0.9 | |
Fortinet FortiManager | >=7.2.0<7.2.4 | |
Fortinet FortiManager | =7.4.0 | |
Fortinet FortiAnalyzer | >=7.2.0<=7.2.5 | |
Fortinet FortiManager | =. | |
Fortinet FortiManager | >=7.2.0<=7.2.3 | |
Fortinet FortiManager | >=7.0.0<=7.0.8 | |
Fortinet FortiManager | >=6.4.0<=6.4.12 | |
Fortinet FortiManager | >=6.2.0<=6.2.11 |
Please upgrade to FortiAnalyzer-BigData version 7.2.6 or above Please upgrade to FortiAnalyzer-BigData version 7.0.7 or above Please upgrade to FortiAnalyzer-BigData version 6.4.8 or above Please upgrade to FortiAnalyzer-BigData version 6.2.6 or above Please upgrade to FortiManager version 7.4.1 or above Please upgrade to FortiManager version 7.2.4 or above Please upgrade to FortiManager version 7.0.9 or above Please upgrade to FortiManager version 6.4.13 or above Please upgrade to FortiManager version 6.2.12 or above Please upgrade to FortiAnalyzer version 7.4.1 or above Please upgrade to FortiAnalyzer version 7.2.4 or above Please upgrade to FortiAnalyzer version 7.0.9 or above Please upgrade to FortiAnalyzer version 6.4.13 or above Please upgrade to FortiAnalyzer version 6.2.12 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42791 has a moderate severity rating due to the potential for unauthorized code execution by low-privileged attackers.
To fix CVE-2023-42791, upgrade FortiManager to version 7.4.1 or later, or to the appropriate remedial version for earlier versions based on your installation.
CVE-2023-42791 affects FortiManager versions 7.4.0, 7.2.0 to 7.2.3, and 7.0.0 to 7.0.8, as well as versions 6.4.0 to 6.4.12 and 6.2.0 to 6.2.11.
Yes, a remote attacker with low privileges could exploit CVE-2023-42791 by sending crafted HTTP requests that leverage the relative path traversal vulnerability.
CVE-2023-42791 is classified as a relative path traversal vulnerability, which is categorized under CWE-23.