A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x and FortiAnalyzer version 7.0.0 through 7.0.3, version 6.4.0 through 6.4.7, 6.2.x and 6.0.x allows attacker to execute arbitrary shell code as `root` user via `diagnose system` CLI commands.
CVSS Details
- CVSS 3.1 Base Score: 7.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortianalyzer | — | Upgrade to the latest version of FortiAnalyzerUpgrade FortiAnalyzer to 6.4.8Upgrade FortiAnalyzer to 7.2.0Upgrade FortiAnalyzer to 7.0.4 | Jul 29, 2022 | Jul 5, 2022 |
| Fortinet Fortimanager | — | Upgrade FortiManager to 7.0.4Upgrade to the latest version of FortiManagerUpgrade FortiManager to 7.2.0Upgrade FortiManager to 6.4.8 | Nov 14, 2022 | Jul 5, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub