CVE-2023-42791: Path traversal via unrestricted file upload
A relative path traversal [CWE-23] vulnerability in FortiManager and FortiAnalyzer may allow a remote attacker with low privileges to execute unauthorized code via crafted HTTP requests.
Other sources
A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 through 6.2.11 allows attacker to execute unauthorized code or commands via crafted HTTP requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-42791?
CVE-2023-42791 has a moderate severity rating due to the potential for unauthorized code execution by low-privileged attackers.
How do I fix CVE-2023-42791?
To fix CVE-2023-42791, upgrade FortiManager to version 7.4.1 or later, or to the appropriate remedial version for earlier versions based on your installation.
Which versions of FortiManager are affected by CVE-2023-42791?
CVE-2023-42791 affects FortiManager versions 7.4.0, 7.2.0 to 7.2.3, and 7.0.0 to 7.0.8, as well as versions 6.4.0 to 6.4.12 and 6.2.0 to 6.2.11.
Can a remote attacker exploit CVE-2023-42791?
Yes, a remote attacker with low privileges could exploit CVE-2023-42791 by sending crafted HTTP requests that leverage the relative path traversal vulnerability.
What type of vulnerability is CVE-2023-42791 classified as?
CVE-2023-42791 is classified as a relative path traversal vulnerability, which is categorized under CWE-23.