{"api_version":"1","generated_at":"2026-07-23T09:49:08+00:00","cve":"CVE-2019-15710","urls":{"html":"https://cve.report/CVE-2019-15710","api":"https://cve.report/api/cve/CVE-2019-15710.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-15710","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-15710"},"summary":{"title":"CVE-2019-15710","description":"An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted \"execute date\" commands.","state":"PUBLIC","assigner":"psirt@fortinet.com","published_at":"2019-10-31 20:15:00","updated_at":"2019-11-06 16:04:00"},"problem_types":["CWE-78"],"metrics":[],"references":[{"url":"https://fortiguard.com/psirt/FG-IR-19-273","name":"https://fortiguard.com/psirt/FG-IR-19-273","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"FortiExtender OS command injection through execute date CLI command | FortiGuard","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-15710","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15710","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"15710","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"fortiguard","cpe5":"fortiextender","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"15710","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"fortiguard","cpe5":"fortiextender","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"15710","vulnerable":"1","versionEndIncluding":"4.1.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fortiguard","cpe5":"fortiextender_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-15710","ASSIGNER":"psirt@fortinet.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Fortinet","product":{"product_data":[{"product_name":"FortiExtender","version":{"version_data":[{"version_value":"4.1.0 to 4.1.1"},{"version_value":"4.0.0 and below"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Execute unauthorized code or commands"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://fortiguard.com/psirt/FG-IR-19-273","url":"https://fortiguard.com/psirt/FG-IR-19-273"}]},"description":{"description_data":[{"lang":"eng","value":"An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted \"execute date\" commands."}]}},"nvd":{"publishedDate":"2019-10-31 20:15:00","lastModifiedDate":"2019-11-06 16:04:00","problem_types":["CWE-78"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9},"severity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fortiguard:fortiextender_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"4.1.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:fortiguard:fortiextender:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"15710","Ordinal":"155237","Title":"CVE-2019-15710","CVE":"CVE-2019-15710","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"15710","Ordinal":"1","NoteData":"An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted \"execute date\" commands.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"15710","Ordinal":"2","NoteData":"2019-10-31","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"15710","Ordinal":"3","NoteData":"2019-11-04","Type":"Other","Title":"Modified"}]}}}