Fortinet FortiWLC CVE-2017-7341 OS Command Injection Vulnerability
BID:101273
CVE-2017-7341 |Info
Fortinet FortiWLC CVE-2017-7341 OS Command Injection Vulnerability
| Bugtraq ID: | 101273 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-7341 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2017 12:00AM |
| Updated: | Oct 13 2017 12:00AM |
| Credit: | Tom Scholten, SOLIDBE B.V. |
| Vulnerable: |
Fortinet FortiWLC 8.3.2 Fortinet FortiWLC 8.3 Fortinet FortiWLC 8.2 Fortinet FortiWLC 8.0 Fortinet FortiWLC 7.0-7 Fortinet FortiWLC 7.0-10 Fortinet FortiWLC 6.1-5 Fortinet FortiWLC 6.1-2 |
| Not Vulnerable: |
Fortinet FortiWLC 8.3.3 Fortinet FortiWLC 7.0.11 |
Discussion
Fortinet FortiWLC CVE-2017-7341 OS Command Injection Vulnerability
Fortinet FortiWLC is prone to an OS command-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker may exploit this issue to inject and execute arbitrary commands within the context of the affected application; this may aid in further attacks.
The following products are affected:
Fortinet FortiWLC 6.1-2 through 6.1-5.
Fortinet FortiWLC 7.0-7 through 7.0-10.
Fortinet FortiWLC 8.0 through 8.2.
Fortinet FortiWLC 8.3.0 through 8.3.2.
Fortinet FortiWLC is prone to an OS command-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker may exploit this issue to inject and execute arbitrary commands within the context of the affected application; this may aid in further attacks.
The following products are affected:
Fortinet FortiWLC 6.1-2 through 6.1-5.
Fortinet FortiWLC 7.0-7 through 7.0-10.
Fortinet FortiWLC 8.0 through 8.2.
Fortinet FortiWLC 8.3.0 through 8.3.2.
Exploit / POC
Fortinet FortiWLC CVE-2017-7341 OS Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Fortinet FortiWLC CVE-2017-7341 OS Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Fortinet FortiWLC CVE-2017-7341 OS Command Injection Vulnerability
References:
References:
- FortiWLC file management OS Command Injection vulnerability (fortiguard.com)
- Fortinet Homepage (Fortinet)