← العودة للجدول
CVE-2023-36553
CVE-2023-36553 — A improper neutralization of special elements used in an os command ('os co
📅 2023-11-14
🔴 Critical 🔥 No NVD Vulnerability Fortinet CVSS 9.8 🎯 EPSS 2.73%

📋 الوصف الكامل

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 and 4.9.0 and 4.7.2 allows attacker to execute unauthorized code or commands via crafted API requests.

💻 الأنظمة المتأثرة

Fortinet

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2023-36553

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v5.4.0 | Fortinet PSIRT Advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←