Improper Handling of Inputs in Fortinet FortiWeb Affects Multiple Versions
CVE-2023-42784

5.5MEDIUM

Key Information:

Vendor
Fortinet
Status
Vendor
CVE Published:
11 March 2025

Summary

An improper handling of syntactically invalid structures in Fortinet FortiWeb versions 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, and 7.0.0 through 7.0.10 can allow attackers to craft malicious HTTP/S requests that lead to unauthorized execution of code or commands. This vulnerability exposes systems to additional security threats, as it enables the exploitation of weak input validation mechanisms.

Affected Version(s)

FortiWeb 7.4.0 <= 7.4.7

FortiWeb 7.2.0 <= 7.2.10

FortiWeb 7.0.0 <= 7.0.10

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.