6.7

CVE-2023-41842

A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet  allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortianalyzer Version >= 6.2.0 < 7.0.10
Fortinet ≫ Fortianalyzer Version >= 7.2.0 < 7.2.4
Fortinet ≫ Fortianalyzer Version >= 7.4.0 < 7.4.2
Fortinet ≫ Fortianalyzer Big Data Version >= 6.4.5 <= 6.4.7
Fortinet ≫ Fortianalyzer Big Data Version >= 7.0.1 <= 7.0.6
Fortinet ≫ Fortianalyzer Big Data Version >= 7.2.0 < 7.2.6
Fortinet ≫ Fortianalyzer Big Data Version 6.2.5
Fortinet ≫ Fortimanager Version >= 6.2.0 < 7.0.10
Fortinet ≫ Fortimanager Version >= 7.2.0 < 7.2.4
Fortinet ≫ Fortimanager Version >= 7.4.0 < 7.4.2
Fortinet ≫ Fortiportal Version >= 5.3.0 < 6.0.15
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.13
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Fortinet 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.