CVE-2023-34992: Fortinet Fortisiem
Critical severity, CVSS 9.8. EPSS: 80.1% chance of exploitation in the next 30 days.
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.
Affected products
- Fortinet Fortisiem: from 6.6.0, up to and including 6.6.3; from 6.7.0, up to and including 6.7.5; version 6.4.0 only; version 6.4.1 only; version 6.4.2 only; version 6.5.0 only; …
Published 2023-10-10. Last modified 2026-06-17.