OS Command Injection Vulnerability in Fortinet FortiWLM
CVE-2023-36549

8.6HIGH

Key Information:

Vendor
Fortinet
Status
Vendor
CVE Published:
10 October 2023

Summary

An OS command injection vulnerability exists in Fortinet FortiWLM versions 8.5.0 to 8.5.4 and 8.6.0 to 8.6.5, allowing attackers to successfully execute unauthorized commands. This issue arises due to improper neutralization of special elements used in operating system commands. Attackers can exploit this vulnerability by crafting malicious HTTP GET request parameters, which may lead to security breaches and exploitation of affected systems. Organizations using these software versions should prioritize upgrading to mitigate potential threats. Further details can be found in the official advisory.

Affected Version(s)

FortiWLM 8.6.0 <= 8.6.5

FortiWLM 8.5.0 <= 8.5.4

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.