Fortinet Addresses Unpatched Critical RCE Vector
ID: edad89f9-d16a-5fb7-9d05-2856928e00d8
STIX ID: report--edad89f9-d16a-5fb7-9d05-2856928e00d8
Feed Name: Dark Reading
Date Published: 2024-12-19
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
Fortinet has patched a critical FortiWLM flaw (CVE-2023-34990, CVSS 9.6) that allows unauthenticated arbitrary log-file reads, which can reveal session IDs and enable access to authenticated endpoints; when chained with a previously patched authenticated command-injection bug (CVE-2023-48782), an attacker can obtain remote code execution with root privileges. The affected FortiWLM versions are 8.6.0–8.6.5 (fixed in 8.6.6+) and 8.5.0–8.5.4 (fixed in 8.5.5+), and administrators are advised to apply vendor patches immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
