PT-2023-27610 · Fortinet · Fortitester

Publicado

2023-12-12

·

Atualizado

2023-12-15

·

CVE-2023-40716

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiTester versions 2.3.0 through 7.2.3
Description An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments when running execute restore/backup.
Recommendations For FortiTester versions 2.3.0 through 7.2.3, consider disabling the execute restore/backup functionality until a patch is available to prevent exploitation. Restrict access to the command line interpreter to minimize the risk of unauthorized command execution. Avoid using specifically crafted arguments when running execute restore/backup until the issue is resolved.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-40716

Produtos afetados

Fortitester