QID 377695
Date Published: 2022-11-16
QID 377695: FortiManager and FortiAnalyzer - OS Command Injection Vulnerability in CLI (FG-IR-22-049)
An improper neutralization of special elements used in an OS command (OS Command Injection) vulnerability [CWE-78] in FortiAnalyzer and FortiManager may allow an authenticated attacker to execute arbitrary shell code as root user via diagnose system CLI commands.
Affected Products:
FortiManager version 7.0.0 through 7.0.3
FortiManager version 6.4.0 through 6.4.7
FortiManager version 6.2.0 through 6.2.9
FortiManager version 6.0.0 through 6.0.11
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiAnalyzer and FortiManager.
Vulnerable version may allow an authenticated attacker to execute arbitrary shell code as root user via diagnose system CLI commands
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-22-049
- FG-IR-22-049 -
www.fortiguard.com/psirt/FG-IR-22-049
CVEs related to QID 377695
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-049 |
|