PT-2024-3043 · Fortinet · Fortimanager

Published

2024-04-09

·

Updated

2025-01-17

·

CVE-2023-47542

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiManager versions 7.4.1 and below FortiManager versions 7.2.4 and below FortiManager version 7.0.10 and below
Description The issue is related to an improper neutralization of special elements used in a template engine, which allows an attacker to execute unauthorized code or commands via specially crafted templates. This can be exploited by creating and using malicious templates to gain unauthorized access or control.
Recommendations For FortiManager versions 7.4.1 and below, update to a version above 7.4.1 to resolve the issue. For FortiManager versions 7.2.4 and below, update to a version above 7.2.4 to resolve the issue. For FortiManager version 7.0.10 and below, update to a version above 7.0.10 to resolve the issue. As a temporary workaround, consider restricting the use of the template engine or limiting access to it until a patch is available.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2024-03227
CVE-2023-47542

Affected Products

Fortimanager