CVE-2023-41838: Fortinet Fortianalyzer

High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.

An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli.

Affected products

  • Fortinet Fortianalyzer: from 6.2.0, up to and including 6.2.11; from 6.4.0, up to and including 6.4.12; from 7.0.0, up to and including 7.0.8; from 7.2.0, up to and including 7.2.3; version 7.4.0 only
  • Fortinet FortiManager: from 6.2.0, up to and including 6.2.11; from 6.4.0, up to and including 6.4.12; from 7.0.0, up to and including 7.0.8; from 7.2.0, up to and including 7.2.3; version 7.4.0 only

Published 2023-10-10. Last modified 2026-06-17.