Fortinet FortiManager Path Traversal Vulnerability Allows Unauthorized Code Execution
CVE-2023-42791
8.8HIGH
Summary
A relative path traversal vulnerability exists in Fortinet FortiManager affecting various versions, enabling attackers to perform unauthorized code execution through specially crafted HTTP requests. By exploiting this vulnerability, attackers can manipulate the relative paths used by the application, potentially gaining access to sensitive files and executing unintended commands. Organizations using affected versions of FortiManager should take immediate steps to apply patches and improve their security posture. For more information and guidance, refer to Fortinet's official advisory.
Affected Version(s)
FortiAnalyzer 7.4.0
FortiAnalyzer 7.2.0 <= 7.2.3
FortiAnalyzer 7.0.0 <= 7.0.8
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved