CVE-2023-28000

6.3MEDIUM

Key Information:

Vendor
Fortinet
Status
Vendor
CVE Published:
13 June 2023

Summary

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC CLI 7.1.0, 7.0.0 through 7.0.3, 6.2.0 through 6.2.4, 6.1 all versions, 6.0 all versions may allow a local and authenticated attacker to execute unauthorized commands via specifically crafted arguments in diagnose system df CLI command.

Affected Version(s)

FortiADC 7.1.0

FortiADC 7.0.0 <= 7.0.3

FortiADC 6.2.0 <= 6.2.4

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.