Path traversal in FortiSIEM - CVE-2023-40714

 

Path traversal in FortiSIEM - CVE-2023-40714

Published: October 11, 2023


Vulnerability identifier: #VU81929
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-40714
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
FortiSIEM
Software vendor:
Fortinet, Inc

Description

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to input validation error when processing directory traversal sequences in FortiSIEM file upload components. A remote authenticated user can send specially crafted HTTP requests to FortiSIEM GUI and overwrite arbitrary files on the system, leading to privilege escalation.


Remediation

Install update from vendor's website.

External links