Sploitus

CVE-2023-42788

No indexed exploits for CVE-2023-42788 yet

An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and version 6.2.0 through 6.2.11 may allow a local attacker with low privileges to execute unauthorized code via specifically crafted arguments to a CLI command

Affected products
Fortianalyzer, Fortimanager
Fortinet Fortianalyzer
≤ 6.2.11, 6.4.12, 7.0.8, 7.2.3, 7.4.0
Fortinet Fortimanager
≤ 6.2.11, 6.4.12, 7.0.8, 7.2.3, 7.4.0
Fix
Available
CVSS 3.1
7.8 HIGH
EPSS
1.3% (69th percentile)
Weakness
CWE-78
NVD status
Modified
Published
2023-10-10

Fix

Please upgrade to FortiAnalyzer version 7.4.1 or above Please upgrade to FortiAnalyzer version 7.2.4 or above Please upgrade to FortiAnalyzer version 7.0.9 or above Please upgrade to FortiAnalyzer version 6.4.13 or above Please upgrade to FortiAnalyzer version 6.2.12 or above Please upgrade to FortiManager version 7.4.1 or above Please upgrade to FortiManager version 7.2.4 or above Please upgrade to FortiManager version 7.0.9 or above Please upgrade to FortiManager version 6.4.13 or above Please upgrade to FortiManager version 6.2.12 or above

CVE-2023-42788 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-42788 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-42788 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.