An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and version 6.2.0 through 6.2.11 may allow a local attacker with low privileges to execute unauthorized code via specifically crafted arguments to a CLI command
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortianalyzer | — | Upgrade FortiAnalyzer to 7.0.9Upgrade FortiAnalyzer to 7.4.1Upgrade FortiAnalyzer to 6.4.13Upgrade FortiAnalyzer to 6.2.12Upgrade FortiAnalyzer to 7.2.4 | Oct 16, 2023 | Oct 10, 2023 |
| Fortinet Fortimanager | — | Upgrade FortiManager to 6.2.12Upgrade FortiManager to 7.0.9Upgrade FortiManager to 7.4.1Upgrade FortiManager to 6.4.13Upgrade FortiManager to 7.2.4 | Oct 16, 2023 | Oct 10, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub