VDB

CVE-2023-40716

CVE-2023-40716 PUBLISHED CVSS 6.5 MEDIUM

An improper neutralization of special elements used in an OS command vulnerability [CWE-78]  in the command line interpreter of FortiTester 2.3.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments when running execute restore/backup .

EPSS 0.07% · 22.6th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:C
EPSS Score
0.07%
22.6th percentile

Affected Products

VendorProductVersions
fortinetfortitester7.2.3, 3.3.0, 3.3.1
FortinetFortiTester7.1.0, 7.0.0, 4.2.0

Exploit Intelligence

Timeline

  • Dec 13, 2023 CVE Published
  • Dec 13, 2023 EPSS Score
  • Jan 7, 2024 PoC Published
  • Jan 11, 2024 EPSS Score
  • Feb 10, 2024 EPSS Score
  • Mar 10, 2024 EPSS Score
  • Apr 8, 2024 EPSS Score
  • May 7, 2024 EPSS Score
  • Jun 6, 2024 EPSS Score
  • Jul 5, 2024 EPSS Score
  • Aug 3, 2024 EPSS Score
  • Sep 1, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›