An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortianalyzer | — | Upgrade FortiAnalyzer to 7.0.9Upgrade FortiAnalyzer to 7.2.4Upgrade FortiAnalyzer to 6.4.13Upgrade FortiAnalyzer to 7.4.1Upgrade FortiAnalyzer to 6.2.12 | Oct 16, 2023 | Oct 10, 2023 |
| Fortinet Fortimanager | — | Upgrade FortiManager to 6.4.13Upgrade FortiManager to 7.2.4Upgrade FortiManager to 7.0.9Upgrade FortiManager to 7.4.1Upgrade FortiManager to 6.2.12 | Oct 16, 2023 | Oct 10, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub