High severity7.1NVD Advisory· Published Oct 10, 2023· Updated Jun 17, 2026
CVE-2023-41838
CVE-2023-41838
Description
An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli.
Affected products
7cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*range: >=6.2.0,<=6.2.11
- cpe:2.3:a:fortinet:fortianalyzer:7.4.0:*:*:*:*:*:*:*
- (no CPE)range: 7.4.0
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*range: >=6.2.0,<=6.2.11
- cpe:2.3:a:fortinet:fortimanager:7.4.0:*:*:*:*:*:*:*
- (no CPE)range: 7.4.0, 7.2.0 through 7.2.3
- (no CPE)range: 7.4.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-23-169nvdVendor Advisory
News mentions
0No linked articles in our index yet.