QID 379605
Date Published: 2024-04-11
QID 379605: Fortinet FortiManager - Code Injection Vulnerability (FG-IR-23-419)
FortiManager provides automation-driven centralized management of your Fortinet devices from a single console.
CVE-2023-47542: An improper neutralization of special elements used in a template engine vulnerability in FortiManager provisioning templates may allow a local authenticated attacker with at least read-only permissions to execute arbitrary code via specially crafted templates.
Affected Products:
FortiManager 7.4.0 through 7.4.1
FortiManager 7.2.0 through 7.2.4
FortiManager 7.0.0 through 7.0.10
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager.
Note: This QID is kept potential because, the signature doesn't check for the workaround
Vulnerable version of FortiManager may allow a local authenticated attacker with at least read-only permissions to execute arbitrary code via specially crafted templates.
For more details refer advisory FG-IR-23-419
Workaround:
Disable "Provisioning Templates" and "Install Policy Package or Device Configuration" privileges.
- FG-IR-23-419 -
fortiguard.fortinet.com/psirt/FG-IR-23-419
CVEs related to QID 379605
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-419 |
|