OS Command Injection Vulnerability in Fortinet FortiWLM
CVE-2023-34987
8.6HIGH
Summary
An OS command injection vulnerability exists in Fortinet FortiWLM versions 8.6.0 to 8.6.5 and 8.5.0 to 8.5.4, allowing attackers to manipulate HTTP GET request parameters to execute unauthorized commands. This flaw can lead to unauthorized access and control over affected systems, potentially compromising the integrity and security of the organization. Proper input validation and sanitization mechanisms are essential to mitigate such risks. For more details, refer to Fortinet's advisory.
Affected Version(s)
FortiWLM 8.6.0 <= 8.6.5
FortiWLM 8.5.0 <= 8.5.4
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved