CVE Vulnerabilities

CVE-2023-34984

Protection Mechanism Failure

Published: Sep 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.

Weakness

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Software

NameVendorStart VersionEnd Version
FortiwebFortinet6.3.6 (including)6.3.23 (including)
FortiwebFortinet6.4.0 (including)6.4.3 (including)
FortiwebFortinet7.0.0 (including)7.0.6 (including)
FortiwebFortinet7.2.0 (including)7.2.1 (including)

References