CVE-2023-34992
CRITICAL 10.0EPSS 80.1%
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.0.0 and 6.7.0 through 6.7.5 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via crafted API requests.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 80.06% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- critical · CWE-78
- Published
- 2023-10-10
- Updated
- 2026-01-14
Proof-of-concept exploits (2)
- horizon3ai/CVE-2023-3499227★ · 2024-05-21
- d0rb/CVE-2023-34992-Checker