peter bassill · operator
$ cve CVE-2023-34992 JSON

CVE-2023-34992

10.0
CRITICAL · CVSS 3.1 · EPSS 80.1% (pctl 100)

Patch early

EPSS 80.1% — above the 10% action threshold.

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS80.06% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2023-10-10
Last modified2026-06-17

Affected (1)

VendorProduct
fortinetfortisiem

References

→ the Explorer  ·  watch your stack  ·  NVD