CVE-2023-34992: OS Command Injection
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.0.0 and 6.7.0 through 6.7.5 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via crafted API requests.
Other sources
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.
— MITRE
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this Fortinet FortiSIEM vulnerability?
The vulnerability ID for this Fortinet FortiSIEM vulnerability is CVE-2023-34992.
What is the severity level of CVE-2023-34992?
The severity level of CVE-2023-34992 is critical with a CVSS score of 9.8.
Which versions of Fortinet FortiSIEM are affected by CVE-2023-34992?
Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.5, 6.6.0 through 6.6.3, 6.5.0 through 6.5.1, 6.4.0 through 6.4.2 are affected by CVE-2023-34992.
What is the impact of CVE-2023-34992?
CVE-2023-34992 allows an attacker to execute unauthorized code or commands via crafted API requests, leading to potential compromise of the Fortinet FortiSIEM system.
Is there a fix available for CVE-2023-34992?
Yes, Fortinet has provided a security advisory with remediation steps to address the vulnerability. Please refer to the reference link for more information.