Lucene search

K
cveFortinetCVE-2023-27995
HistoryApr 11, 2023 - 5:15 p.m.

CVE-2023-27995

2023-04-1117:15:08
CWE-1336
fortinet
web.nvd.nist.gov
19
cve-2023-27995
vulnerability
fortinet
fortisoar
code execution
template engine

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

55.6%

A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.

Affected configurations

Nvd
Node
fortinetfortisoarRange7.3.07.3.2
VendorProductVersionCPE
fortinetfortisoar*cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Fortinet",
    "product": "FortiSOAR",
    "defaultStatus": "unaffected",
    "versions": [
      {
        "versionType": "semver",
        "version": "7.3.0",
        "lessThanOrEqual": "7.3.1",
        "status": "affected"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

55.6%

Related for CVE-2023-27995