ID

VAR-202311-1151


CVE

CVE-2023-42783


DESCRIPTION

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.2 through 8.4.0 and 8.3.2 through 8.3.0 and 8.2.2 allows attacker to read arbitrary files via crafted http requests.

Trust: 1.0

sources: NVD: CVE-2023-42783

AFFECTED PRODUCTS

vendor:fortinetmodel:fortiwlmscope:lteversion:8.6.6

Trust: 1.0

vendor:fortinetmodel:fortiwlmscope:eqversion:8.3.1

Trust: 1.0

vendor:fortinetmodel:fortiwlmscope:eqversion:8.3.0

Trust: 1.0

vendor:fortinetmodel:fortiwlmscope:eqversion:8.4.1

Trust: 1.0

vendor:fortinetmodel:fortiwlmscope:lteversion:8.5.4

Trust: 1.0

vendor:fortinetmodel:fortiwlmscope:eqversion:8.4.0

Trust: 1.0

vendor:fortinetmodel:fortiwlmscope:eqversion:8.3.2

Trust: 1.0

vendor:fortinetmodel:fortiwlmscope:gteversion:8.6.0

Trust: 1.0

vendor:fortinetmodel:fortiwlmscope:gteversion:8.5.0

Trust: 1.0

vendor:fortinetmodel:fortiwlmscope:eqversion:8.4.2

Trust: 1.0

vendor:fortinetmodel:fortiwlmscope:eqversion:8.2.2

Trust: 1.0

sources: NVD: CVE-2023-42783

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-42783
value: HIGH

Trust: 1.0

psirt@fortinet.com: CVE-2023-42783
value: HIGH

Trust: 1.0

nvd@nist.gov: CVE-2023-42783
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 2.0

sources: NVD: CVE-2023-42783 // NVD: CVE-2023-42783

PROBLEMTYPE DATA

problemtype:CWE-23

Trust: 1.0

sources: NVD: CVE-2023-42783

EXTERNAL IDS

db:NVDid:CVE-2023-42783

Trust: 1.0

sources: NVD: CVE-2023-42783

REFERENCES

url:https://fortiguard.com/psirt/fg-ir-23-143

Trust: 1.0

sources: NVD: CVE-2023-42783

SOURCES

db:NVDid:CVE-2023-42783

LAST UPDATE DATE

2024-08-14T14:36:31.951000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2023-42783date:2023-11-18T03:28:03.087

SOURCES RELEASE DATE

db:NVDid:CVE-2023-42783date:2023-11-14T18:15:53.853