VDB

CVE-2023-42791

CVE-2023-42791 PUBLISHED CVSS 8.600000381469727 HIGH

A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 through 6.2.11 allows attacker to execute unauthorized code or commands via crafted HTTP requests.

EPSS 4.18% · 90.1th percentile

Risk Scores

CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:X
EPSS Score
4.18%
90.1th percentile

Affected Products

VendorProductVersions
fortinetfortimanager7.2.0, 7.0.0, 7.4.0
fortinetfortimanager6.2.0, 6.4.0, 7.0.0
fortinetfortianalyzer7.0.0, 6.2.0, 7.4.0
FortinetFortiAnalyzer7.2.0, 7.0.0, 6.4.0
FortinetFortiManager7.4.0, 7.2.0, 7.0.0

Timeline

  • Feb 20, 2024 CVE Published
  • Feb 21, 2024 EPSS Score
  • Mar 19, 2024 EPSS Score
  • May 12, 2024 EPSS Score
  • Jun 8, 2024 EPSS Score
  • Aug 1, 2024 EPSS Score
  • Aug 2, 2024 CVE Updated
  • Aug 28, 2024 EPSS Score
  • Oct 20, 2024 EPSS Score
  • Nov 16, 2024 EPSS Score
  • Jan 10, 2025 EPSS Score
  • Feb 6, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›