SB2023050444 - Multiple vulnerabilities in FortiADC
Published: May 4, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) OS Command Injection (CVE-ID: CVE-2023-27999)
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation. A local user attacker can execute unauthorized commands via specifically crafted arguments to existing commands.
2) Path traversal (CVE-ID: CVE-2023-27993)
The vulnerability allows a local user to delete arbitrary directories.
The vulnerability exists due to input validation error when processing directory traversal sequences in CLI. A local user can execute a specially crafted CLI command and delete arbitrary directories on the system.
Remediation
Install update from vendor's website.