← Back to browse · API

CVE-2023-34993

Severity
CRITICAL
CVSS
9.6
EPSS
0.18148
Risk score
44.75
CISA KEV
No
PoC
No
Published
2023-10-10
Modified
2024-09-19
First seen
2026-08-07
Aliases
EUVD-2023-39031, GHSA-HP4R-WH6M-675V
Products
Fortinet:FortiWLM 8.5.0 ≤8.5.4, Fortinet:FortiWLM 8.6.0 ≤8.6.5
Sources
euvd EUVD-2023-39031

Description

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

References