CVE-2023-34984
CVE-2023-34984 is a high-severity vulnerability in Fortinet Fortiweb with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-693.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- EPSS exploit prediction: 1% (53rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-693
- Affected product: Fortinet Fortiweb
- Published:
- Last modified:
Description
A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.
Frequently asked questions
- What is CVE-2023-34984?
- A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.
- How severe is CVE-2023-34984?
- CVE-2023-34984 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with high attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2023-34984 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (53rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-34984?
- CVE-2023-34984 affects Fortinet Fortiweb. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-34984?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2023-34984 published?
- CVE-2023-34984 was published on 2023-09-13 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
More vulnerabilities in Fortinet Fortiweb
- CVE-2026-26035 — Critical (CVSS 9.8): An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb…
- CVE-2026-24858 — Critical (CVSS 9.8): An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet…
- CVE-2025-59719 — Critical (CVSS 9.8): An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through…
- CVE-2025-64446 — Critical (CVSS 9.8): A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4,…
- CVE-2025-25257 — Critical (CVSS 9.8): An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89]…
- CVE-2023-25610 — Critical (CVSS 9.8): A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version…
All CVEs affecting Fortinet Fortiweb →
Other CWE-693 (Protection Mechanism Failure) vulnerabilities
- CVE-2026-93606 — Critical (CVSS 10.0): vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host…
- CVE-2026-93605 — Critical (CVSS 10.0): vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits…
- CVE-2026-92956 — Critical (CVSS 10.0): vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on…
- CVE-2026-75874 — Critical (CVSS 10.0): Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154,…
- CVE-2026-47140 — Critical (CVSS 10.0): vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins…
- CVE-2026-34208 — Critical (CVSS 10.0): SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects…
Browse all CWE-693 (Protection Mechanism Failure) vulnerabilities →