CVE-2023-34990

Published Dec 18, 2024

Last updated 5 months ago

Overview

Description
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.
Source
psirt@fortinet.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@fortinet.com
CWE-23
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-94

Social media

Hype score
Not currently trending
  1. Fortinet FortiWLM の深刻な脆弱性 CVE-2023-34990 (CVSS 9.8) が FIX:ただちにアップデートを! https://t.co/CG45Yg1QLx Fortinet の3つの脆弱性が FIX しました。文中のリンク先にある Horizo​​https://t.co/FQyPrgubT9 のレポートですが、その日付は 5月14日であり、CVE… https://t.co/uqTjTdLAnT

    @iototsecnews

    26 Dec 2024

    14 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Fortinet Addresses Unpatched Critical RCE Vector: An Analysis of Cybersecurity and Corporate Responsibility (CVE-2023-34990) https://t.co/uRTxWiXXwr

    @TMJIntel

    26 Dec 2024

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🛑 Fortinet's Wireless LAN Manager (FortiWLM) is vulnerable to a path traversal flaw (CVE-2023-34990) with a 9.6/10 CVSS score. Why it’s urgent: It allows attackers to... 1️⃣ Access admin accounts using static session IDs. 2️⃣ Execute unauthorized commands by chaining… https

    @Cyberwald_talks

    24 Dec 2024

    38 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Fortinet has recently addressed a critical security flaw (CVE-2023-34990) in its Wireless LAN Manager (FortiWLM). https://t.co/hdkbM6kGtP

    @VULNERAsecurity

    23 Dec 2024

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Critical FortiWLM vulnerability (CVE-2023-34990) allows sensitive data disclosure & potential code execution. Update to latest versions immediately! #FortiWLM #Cybersecurity #Vulnerability https://t.co/sNAjYBs2TX

    @TLDRStories

    23 Dec 2024

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Fortinet、FortiWLMのCriticalな脆弱性について通知が出ている:CVE-2023-34990 https://t.co/daCWCCimwb #虎吉テクノロジー

    @sgr_b214

    22 Dec 2024

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Top 5 Trending CVEs: 1 - CVE-2024-54150 2 - CVE-2023-34990 3 - CVE-2024-12356 4 - CVE-2024-56145 5 - CVE-2024-12727 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    22 Dec 2024

    161 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. به تازگی دو آسیب پذیری خطرناک برای محصولات FortiManager با کد شناسایی CVE-2024-48889 از نوع OS command execution و FortiWLM با کد شناسایی CVE-2023-34990 از نوع File Read منتشر شده است. نسخه های مختلفی از FortiManager دارای این آسیب پذیری هستند . https://t.co/Poz3aKYxT1 https://t.

    @AmirHossein_sec

    21 Dec 2024

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Fortinet alerte sur une faille critique dans FortiWLM avec risque d'exploitation pour accès admin. Vulnérabilité CVE-2023-34990 avec un score CVSS de 9.6. Analystes Sécurité, restez informés! #Cybersecurite #ZeroDay 👉 https://t.co/ztFcu2Y1hy

    @CyberAlertFr

    21 Dec 2024

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. #Fortinet has now patched CVE-2023-34990, an unauthenticated limited file read vulnerability that was first reported in March by @hacks_zach. For more details and insight from Zach, head to https://t.co/uAV99P8pF9. #NodeZero #pentesting #infosec

    @Horizon3ai

    20 Dec 2024

    1301 Impressions

    7 Retweets

    16 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  11. 🚨 Fortinet warns of a critical vulnerability (CVE-2023-34990) in FortiWLM, allowing remote attackers to exploit sensitive info through path traversal. High risk of unauthorized access! 🔒 #FortiWLMFlaw #PathTraversal #FortinetAdvisory #CybersecurityNews… https://t.co/BmKHY34Rg8

    @TweetThreatNews

    20 Dec 2024

    51 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Fortinet issued an advisory for a now-patched critical flaw impacting Wireless LAN Manager. (FortiWLM) that could lead to disclosure of sensitive information. The vulnerability, tracked as CVE-2023-34990, with a CVSS score of 9.6 out of a maximum of 10.0. https://t.co/fkTh86jBEY

    @riskigy

    20 Dec 2024

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. CVE-2023-34990: Critical FortiWLM Vulnerability Exposes Sensitive Information https://t.co/xbaL3SQeqB

    @_havij

    20 Dec 2024

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Fortinet has warned of a critical security flaw in FortiWLM, tracked as CVE-2023-34990, which could allow remote attackers to exploit a path traversal vulnerability to access sensitive files; it has a CVSS score of 9.6. #Fortinet #CyberSecurity https://t.co/zrlh1SECnD

    @Cyber_O51NT

    20 Dec 2024

    141 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  15. Fortinet has issued an advisory for a now-patched critical security flaw impacting Wireless LAN Manager (FortiWLM) that could lead to disclosure of sensitive information. Tracked as CVE-2023-34990, carries a CVSS score of 9.6 out of a maximum of 10.0. https://t.co/fkTh86jBEY http

    @riskigy

    20 Dec 2024

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. #Vulnerability #CVE202334990 CVE-2023-34990 (CVSS 9.8): Critical Security Flaw Found in Fortinet FortiWLM https://t.co/BcIDNcunMq

    @Komodosec

    19 Dec 2024

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. ⚠️ Fortinet's WLAN Manager (CVE-2023-34990, CVSS 9.6) allows admin access via static IDs, unauthorized commands, and quick root access. Read : https://t.co/RoW2SgSMQz #CyberAlert #Vulnerability Follow For More News

    @soap2you

    19 Dec 2024

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. ⚠️🌎Alerta: Fortinet ha emitido un aviso sobre una falla de seguridad crítica que ya ha sido corregida y que afecta a Wireless LAN Manager (FortiWLM) y que podría llevar a la divulgación de información confidencial. La vulnerabilidad es identificada como CVE-2023-34990. https://

    @victor_ruiz

    19 Dec 2024

    1402 Impressions

    15 Retweets

    25 Likes

    1 Bookmark

    1 Reply

    1 Quote

  19. 🚨 Vulnérabilités critiques chez Fortinet : Deux failles (CVE-2024-48889 & CVE-2023-34990) permettent l’exécution de code à distance et l’accès à des données sensibles sur FortiManager et FortiWLM. Mettez à jour. Téléchargez le bulletin d'alerte. https://t.co/52pLbTadJ9 https

    @cert_tg

    19 Dec 2024

    89 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  20. Fortinet fixes several vulnerabilities including CVE-2023-34990 #Fortinet #CVE-2023-34990 #CVE-2024-50570 #CVE-2024-48889 https://t.co/jEOWPiIZpJ

    @pravin_karthik

    19 Dec 2024

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Fortinet Flaw Frenzy: Patch Now or Risk Admin Access Hijinks! Hot Take: Looks like Fortinet’s Wireless LAN Manager had a “come as you are” party for hackers, but luckily the bouncer, CVE-2023-34990, has been kicked out. Grab your patches, folks, before your sensitive data gets…

    @TheNimbleNerd

    19 Dec 2024

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Youpi, Fortinet émet un avis de sécurité pour sa fonction Wireless LAN Manager (FortiWLM) ayant la mention CVE-2023-34990. En gros, un accès a des fichiers sensible du firewall est possible Plus d'info 👇 https://t.co/JxxSkdYTdI

    @_Nidouille_

    19 Dec 2024

    980 Impressions

    5 Retweets

    12 Likes

    0 Bookmarks

    1 Reply

    1 Quote

  23. Fortinet Wireless LAN Manager Vulnerable to Path Traversal Bug (CVE-2023-34990) with CVSS 9.6/10 The vulnerability lets attackers exploit static session IDs for admin access, chain flaws to run unauthorized commands, and escalate to root access quickly. https://t.co/iqc6vJw58Y

    @iProtectCSS

    19 Dec 2024

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. FortinetのFortiWLMの特定バージョン(8.6.0~8.6.5および8.5.0~8.5.4)において、攻撃者が特別に作成したWebリクエストを使用して、不正なコードやコマンドを実行できる相対パス・トラバーサルの脆弱性が発見されました。 CVE-2023-34990 CVSS9.6 アップデートを適用することを推奨します。 https://t.co/zx9eF5IBHv

    @t_nihonmatsu

    19 Dec 2024

    259 Impressions

    0 Retweets

    5 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  25. 🛑 Fortinet's Wireless LAN Manager is vulnerable to a path traversal bug (CVE-2023-34990) with a 9.6/10 CVSS score. It let attackers: 1️⃣ access admin using static session IDs 2️⃣ execute unauthorized commands by chaining flaws 3️⃣ gain root in minutes https://t.co/ZHkxkdbA0v

    @TheHackersNews

    19 Dec 2024

    11705 Impressions

    43 Retweets

    84 Likes

    13 Bookmarks

    0 Replies

    2 Quotes

  26. 🚨 CVE Alert: Critical Fortinet FortiWLM Path Traversal Vulnerability 🚨 Vulnerability Details: CVE-2023-34990 (CVSS v3 9.8/10) Fortinet FortiWLM Path Traversal Vulnerability Impact A Successful exploit may allow a remote unauthenticated attacker to read sensitive files.… http

    @CyberxtronTech

    19 Dec 2024

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 🚨 CVE-2023-34990 (Published: 2024-12-18) - High severity vulnerability in Fortinet products. Affects specific versions; ensure your systems are updated! For remediation details, check the official advisory: https://t.co/S4lF9ESsRh. Stay secure! 🔒 #CyberSecurity #Fortinet

    @transilienceai

    19 Dec 2024

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 🚨 CVE-2023-34990 (Published: 2024-12-18) - High severity vulnerability in Fortinet products. Affects multiple versions. Remediation is crucial! For detailed guidance and updates, visit: https://t.co/S4lF9ESsRh. Stay secure! 🔒 #CyberSecurity #Fortinet #CVE

    @transilienceai

    19 Dec 2024

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. 🚨 CVE-2023-34990 (Published: 2024-12-18) - A high-severity vulnerability in Fortinet products. Affected versions are at risk of exploitation. Immediate remediation is crucial! Check out the details and recommended fixes here: https://t.co/S4lF9ESsRh #CyberSecurity #Fortinet… htt

    @transilienceai

    19 Dec 2024

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 🚨 CVE-2023-34990 (Published: 2024-12-18) - High severity vulnerability in Fortinet products. Affects multiple versions. Remediation is crucial! Ensure your systems are updated and patched. For more details, check the advisory: https://t.co/S4lF9ESsRh #CyberSecurity #Fortinet

    @transilienceai

    19 Dec 2024

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. 🚨 CVE-2023-34990 (Published: 2024-12-18) - A high-severity vulnerability affects Fortinet products. Ensure your systems are updated to the latest versions to mitigate risks. For detailed remediation steps, visit: https://t.co/S4lF9ESsRh. Stay secure! 🔒 #CyberSecurity #Fortinet

    @transilienceai

    19 Dec 2024

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. 🚨 CVE-2023-34990 (Published: 2024-12-18) - High severity vulnerability in Fortinet products. Affected versions include Fortinet nan. 🛡️ Remediation is crucial! Check out the details and recommended fixes here: https://t.co/S4lF9ESsRh #CyberSecurity #Fortinet #VulnerabilityAlert

    @transilienceai

    19 Dec 2024

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. CVE-2023-34990 (CVSS 9.8): Critical Security Flaw Found in Fortinet FortiWLM Critical vulnerabilities in Fortinet products - FortiClient VPN, FortiManager, and FortiWLM. Stay safe from CVE-2023-34990 with the latest updates https://t.co/h06aB54Dwz

    @the_yellow_fall

    19 Dec 2024

    817 Impressions

    6 Retweets

    11 Likes

    0 Bookmarks

    0 Replies

    2 Quotes

  34. CVE-2023-34990 A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specia… https://t.co/jzcji2XkC5

    @CVEnew

    18 Dec 2024

    220 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. [CVE-2023-34990: CRITICAL] Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 to 8.5.4 are vulnerable to cyber attacks enabling unauthorized code execution through manipulated web requests.#cybersecurity,#vulnerability https://t.co/nw6oLhIj8G https://t.co/fTa4A2kT0Z

    @CveFindCom

    18 Dec 2024

    80 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.