PT-2024-2113 · Fortinet · Fortianalyzer+3
Published
2024-03-12
·
Updated
2024-03-21
·
CVE-2023-41842
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiManager versions 7.2.0 through 7.2.3 and 7.4.0 through 7.4.1 and before 7.0.10
Fortinet FortiAnalyzer versions 7.2.0 through 7.2.3 and 7.4.0 through 7.4.1 and before 7.0.10
Fortinet FortiAnalyzer-BigData before 7.2.5
Fortinet FortiPortal version 5.3 and version 6.0
Description
The issue is related to the use of an externally-controlled format string, which can be exploited by a privileged attacker to execute unauthorized code or commands via specially crafted command arguments. This is a result of a
CWE-134 vulnerability.Recommendations
For Fortinet FortiManager versions 7.2.0 through 7.2.3 and 7.4.0 through 7.4.1 and before 7.0.10, update to a version that includes the fix for this issue.
For Fortinet FortiAnalyzer versions 7.2.0 through 7.2.3 and 7.4.0 through 7.4.1 and before 7.0.10, update to a version that includes the fix for this issue.
For Fortinet FortiAnalyzer-BigData before 7.2.5, update to version 7.2.5 or later.
For Fortinet FortiPortal version 5.3 and version 6.0, consider disabling the vulnerable functionality until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for Fortinet FortiPortal.
Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortianalyzer
Fortianalyzer-Bigdata
Fortimanager
Fortiportal