Incomplete Cleanup Vulnerability in FortiOS and FortiProxy by Fortinet
CVE-2023-29184
3.1LOW
What is CVE-2023-29184?
A vulnerability exists in FortiOS and FortiProxy that allows a privileged attacker to stealthily add SSH key files to the system. This can be exploited through specially crafted CLI requests, leading to unauthorized access and potential system compromise. It is crucial for users of affected versions to implement necessary security measures and updates to mitigate risks.
Affected Version(s)
FortiOS 7.2.0 <= 7.2.11
FortiOS 7.0.0 <= 7.0.17
FortiOS 6.4.0 <= 6.4.16