CVE-2023-45590: [FortiClient Linux] Remote Code Execution due to dangerous nodejs configuration
An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute unauthorized code or commands via tricking a FortiClientLinux user into visiting a malicious website
Other sources
An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientLinux may allow##an unauthenticated attacker to execute arbitrary code via tricking a FortiClientLinux user into visiting a malicious website.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45590?
CVE-2023-45590 has been classified with a critical severity due to its potential for arbitrary code execution.
How do I fix CVE-2023-45590?
To fix CVE-2023-45590, update FortiClientLinux to version 7.2.1 or 7.0.11 or later.
What versions of FortiClientLinux are affected by CVE-2023-45590?
Affected versions include FortiClientLinux 7.2.0, 7.0.6 to 7.0.10, and 7.0.3 to 7.0.4.
What type of vulnerability is CVE-2023-45590?
CVE-2023-45590 is a code injection vulnerability that allows attackers to execute unauthorized commands.
How does an attacker exploit CVE-2023-45590?
An attacker can exploit CVE-2023-45590 by tricking a user into visiting a malicious website that leads to code execution.