CVE-2023-25608CWE-792

An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-W2 7.2.0 through 7.2.1…

Medium · published September 13, 2023

CVSS v3.1
5.2
EPSS
0%
Percentile
40.8
In the wild
Unconfirmed
What it is

An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-W2 7.2.0 through 7.2.1, 7.0.3 through 7.0.5, 7.0.0 through 7.0.1, 6.4 all versions, 6.2 all versions, 6.0 all versions; FortiAP-C 5.4.0 through 5.4.4, 5.2 all versions; FortiAP 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions, 6.0 all versions; FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to read arbitrary files via specially crafted command arguments.

The record
Technical detail
CVSS v3.1
5.2 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:U/RC:C
CVSS v4.0
Not supplied
EPSS
0.00496 · 40.8th percentile
Weakness
CWE-792 · Incomplete Filtering of One or More Instances of Special Elements
Published
2023-09-13T12:28Z
EPSS history
Timeline
  • 13 SEP 12:28Z
    An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-W2 7.2.0 through 7.2.1…
    cvelistv5