Security Bulletin

CVE-2023-45590: FortiClient Linux Remote Code ExecutionDue to Dangerous Nodejs Configuration

Bulletin: a Fortinet FortiClient for Linux vulnerability stemming from a dangerous Node.js configuration. CVE details, affected versions, and mitigation steps from our SOC.

An Improper Control of Generation of Code (Code Injection) vulnerability — CWE-94 — in FortiClientLinux may allow an unauthenticated attacker to execute arbitrary code by tricking a FortiClientLinux user into visiting a malicious website.

CVE-2023-45590 details

  • Severity: Critical — CVSS 9.4/10
  • Exploitation status: No evidence of exploitation in the wild at time of publication
  • CVE ID: CVE-2023-45590

Impact

Exploitation could allow execution of unauthorized code or commands, and potentially allow an unauthenticated attacker to execute arbitrary code by tricking a FortiClientLinux user into visiting a malicious website.

Affected products & remediation

Version Affected Remediation
FortiClientLinux 7.27.2.0Upgrade to 7.2.1 or above
FortiClientLinux 7.07.0.3 through 7.0.4 · 7.0.6 through 7.0.10Upgrade to 7.0.11 or above

References

  1. FortiGuard Labs PSIRT — FG-IR-23-087
  2. The Hacker News coverage

What Digital Hands is doing

Without signs of exploitation and absent published Tactics, Techniques, and Procedures (TTPs) and Indicators of Compromise (IOCs), Digital Hands continues to monitor for new developments related to CVE-2023-45590. We'll update this bulletin as the situation evolves. Talk to a Cyber Expert if you'd like Digital Hands to monitor your environment.

Back to Blog

Ready to Get There First?

Talk to a Cyber Expert