CRITICAL🇵🇱 Wersja polska

CVE-2023-34990

CVSS 9.8v3.1pub. 2024-12-18upd. 2025-06-05

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.

🤖 AI Analysis
How it works

The attacker sends specially crafted HTTP requests to the vulnerable FortiWLM server, exploiting improper handling of relative file paths (relative path traversal, CWE-23). This mechanism enables escaping the permitted file system area and accessing resources that should have restricted access. Combined with code injection and execution capabilities (CWE-94), the attacker can cause arbitrary commands to be executed on the server. The entire attack requires neither authentication nor user interaction.

Impact

An attacker can gain full control over the vulnerable system, including executing arbitrary code or system commands, which may lead to violations of confidentiality, integrity, and availability of the device and managed wireless infrastructure.

Mitigation & patch

Fortinet FortiWLM should be updated to versions beyond the 8.5.x and 8.6.x branches in accordance with the manufacturer's recommendations available at https://fortiguard.com/psirt/FG-IR-23-144. Until a patch is deployed, it is recommended to restrict access to the FortiWLM management interface exclusively to trusted IP addresses.

Who is affected

Fortinet FortiWLM in versions 8.6.0 – 8.6.5 and 8.5.0 – 8.5.4

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Fortinet Fortiwlm

    APP
    Fortinet
    8.5.0 – 8.5.5 (excl.)8.6.0 – 8.6.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2023-34991CRITICAL9.8PL ✓same product

SQL Injection w Fortinet FortiWLM umożliwiający wykonanie nieautoryzowanego kodu

CVE-2023-36547CRITICAL9.8PL ✓same product

Command injection w Fortinet FortiWLM umożliwiający zdalne wykonanie kodu

CVE-2023-34993CRITICAL9.8PL ✓same product

Command injection w Fortinet FortiWLM umożliwia zdalne wykonanie kodu

CVE-2023-36548CRITICAL9.8PL ✓same product

Command injection w Fortinet FortiWLM via parametry HTTP GET

CVE-2023-36550CRITICAL9.8PL ✓same product

Command injection w Fortinet FortiWLM umożliwiający RCE bez uwierzytelnienia