PT-2023-3049 · Fortinet · Fortiweb
Published
2023-02-16
·
Updated
2023-02-24
·
CVE-2023-23783
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiWeb versions 6.4.0 through 7.0.1
FortiWeb version 7.0.0 through 7.0.1
Description
The issue is related to a use of externally-controlled format string in FortiWeb, allowing an attacker to execute unauthorized code or commands via specially crafted command arguments. This can enable an attacker to run arbitrary code.
Recommendations
For FortiWeb versions 6.4.0 through 7.0.1, update to a version that fixes the use of externally-controlled format strings to prevent code execution.
For FortiWeb version 7.0.0 through 7.0.1, consider restricting access to command arguments until a patch is available.
Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiweb