PT-2023-3049 · Fortinet · Fortiweb
Publicado
2023-02-16
·
Atualizado
2023-02-24
·
CVE-2023-23783
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiWeb versions 6.4.0 through 7.0.1
FortiWeb version 7.0.0 through 7.0.1
Description
The issue is related to a use of externally-controlled format string in FortiWeb, allowing an attacker to execute unauthorized code or commands via specially crafted command arguments. This can enable an attacker to run arbitrary code.
Recommendations
For FortiWeb versions 6.4.0 through 7.0.1, update to a version that fixes the use of externally-controlled format strings to prevent code execution.
For FortiWeb version 7.0.0 through 7.0.1, consider restricting access to command arguments until a patch is available.
Correção
Use of Externally-Controlled Format String
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fortiweb