image credit: Unsplash

A critical OS command injection flaw affects Fortinet FortiSIEM

November 17, 2023

Fortinet is warning customers of a critical OS command injection vulnerability, tracked as CVE-2023-36553 (CVSS score 9.3), in FortiSIEM report server. A remote, unauthenticated attacker can exploit the flaw to execute commands by sending specially crafted API requests.

“An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiSIEM report server may allow a remote unauthenticated attacker to execute unauthorized commands via crafted API requests.” reads the advisory published by the vendor. “This vulnerability was internally discovered as a variant of FG-IR-23-130.”

Read More on Security Affairs