CVE-2023-34990 is a critical relative path traversal vulnerability affecting Fortinet FortiWLM versions 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4. This flaw allows an unauthenticated attacker to execute unauthorized code or commands via specially crafted web requests. With a CVSS score of 9.8 (Critical), it poses a severe risk, enabling complete compromise of confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, public exploit code (Nuclei templates) is available, and its high EPSS score (0.66334) combined with active community discussion and media coverage indicates a significant and immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.5.0, < 8.5.5CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiwlm:*:*:*:*:*:*:*:* | ||
>= 8.6.0, < 8.6.6CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiwlm:*:*:*:*:*:*:*:* | ||
>= 8.5.0, <= 8.5.4CPE match | cpe:2.3:a:fortinet:fortiwlm:*:*:*:*:*:*:*:* | ||
>= 8.6.0, <= 8.6.5CPE match | cpe:2.3:a:fortinet:fortiwlm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.