First published: Tue Oct 10 2023(Updated: )
An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow a local attacker with low privileges to execute unauthorized code via specifically crafted arguments to a CLI command
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAnalyzer | =. | |
Fortinet FortiAnalyzer | >=7.2.0<=7.2.3 | |
Fortinet FortiAnalyzer | >=7.0.0<=7.0.8 | |
Fortinet FortiAnalyzer | >=6.4.0<=6.4.12 | |
Fortinet FortiAnalyzer | >=6.2.0<=6.2.11 | |
Fortinet FortiAnalyzer-BigData | >=7.2.0<=7.2.5 | |
Fortinet FortiAnalyzer-BigData | >=7.0.1<=7.0.6 | |
Fortinet FortiAnalyzer-BigData | >=6.4 | |
Fortinet FortiAnalyzer-BigData | >=6.2 | |
Fortinet FortiManager | =. | |
Fortinet FortiManager | >=7.2.0<=7.2.3 | |
Fortinet FortiManager | >=7.0.0<=7.0.8 | |
Fortinet FortiManager | >=6.4.0<=6.4.12 | |
Fortinet FortiManager | >=6.2.0<=6.2.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The FG-IR-23-167 vulnerability is classified with a high severity due to its potential for unauthorized code execution.
To remediate FG-IR-23-167, upgrade to the appropriate version of FortiManager or FortiAnalyzer that meets the specified remediation version.
FG-IR-23-167 affects users of FortiManager, FortiAnalyzer, and FortiAnalyzer-BigData across several specific versions.
FG-IR-23-167 is a local attack vector, meaning a low-privileged local user can exploit this vulnerability to execute unauthorized commands.
OS Command Injection in FG-IR-23-167 refers to improper neutralization of special elements, allowing attackers to execute arbitrary operating system commands.