← Back to browse · API

CVE-2023-34992

Severity
CRITICAL
CVSS
9.7
EPSS
0.80061
Risk score
66.82
CISA KEV
No
PoC
No
Published
2023-10-10
Modified
2026-01-14
First seen
2026-08-07
Aliases
EUVD-2023-39030, GHSA-22FJ-HQ2R-QCPQ
Products
Fortinet:FortiSIEM 6.4.0 ≤6.4.2, Fortinet:FortiSIEM 6.5.0 ≤6.5.1, Fortinet:FortiSIEM 6.6.0 ≤6.6.3, Fortinet:FortiSIEM 6.7.0 ≤6.7.5, Fortinet:FortiSIEM 7.0.0
Sources
euvd EUVD-2023-39030

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.

References