CVE-2022-27483
Summary
| CVE | CVE-2022-27483 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-19 14:15:00 UTC |
| Updated | 2022-07-27 07:18:00 UTC |
| Description | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x and FortiAnalyzer version 7.0.0 through 7.0.3, version 6.4.0 through 6.4.7, 6.2.x and 6.0.x allows attacker to execute arbitrary shell code as `root` user via `diagnose system` CLI commands. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| PSIRT Advisories | FortiGuard |
CONFIRM |
fortiguard.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377695 FortiManager and FortiAnalyzer - OS Command Injection Vulnerability in CLI (FG-IR-22-049)
- 43933 FortiAnalyzer and FortiManager - OS command injection vulnerability in CLI (FG-IR-22-049)