H-ISAC TLP White Fortinet Patches Critical FortiWLM Vulnerability CVE-2023-34990 – December 27, 2024

On December 18, 2024, FortiGuard Labs published a security advisory disclosing a vulnerability in FortiWLM, a wireless device management application by Fortinet. The flaw, tracked as CVE-2023-34990, has a CVSS score of 9.6, indicating its critical nature.

This vulnerability is a relative path traversal issue, which could allow remote, unauthenticated threat actors to access sensitive files. According to the National Vulnerability Database (NVD), the flaw also enables attackers to execute unauthorized code through specially crafted web requests. The NVD assigned a CVSS score of 9.8 to this vulnerability, which is higher than the score given by Fortinet.

View the detailed report below.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272