CVE-2023-47540: OS Command Injection
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.0.5 through 3.0.7 allows attacker to execute unauthorized code or commands via CLI.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47540?
CVE-2023-47540 is rated as a critical vulnerability due to its potential for os command injection leading to unauthorized code execution.
How do I fix CVE-2023-47540?
To fix CVE-2023-47540, upgrade Fortinet FortiSandbox to a version above 4.4.2, 4.2.6, 4.0.5, or 3.2.4.
What versions of FortiSandbox are affected by CVE-2023-47540?
CVE-2023-47540 affects FortiSandbox versions 3.0.5 through 3.0.7, 4.0.0 through 4.0.5, 4.2.0 through 4.2.6, and 4.4.0 through 4.4.2.
What are the potential impacts of CVE-2023-47540?
The potential impacts of CVE-2023-47540 include unauthorized access and execution of arbitrary commands on affected systems.
Is there a workaround for CVE-2023-47540?
Currently, Fortinet recommends upgrading to secure versions as the primary mitigation for CVE-2023-47540, with no official workaround provided.