QID 44046
Date Published: 2023-05-31
QID 44046: FortiOS - Privilege Escalation Vulnerability via switch-control CLI command (FG-IR-21-242) (Unauthenticated Check)
An improper neutralization of special elements used in an OS command (OS Command Injection) vulnerability [CWE-78] in FortiOS may allow an authenticated attacker to execute privileged commands on a linked FortiSwitch via diagnostic CLI commands.
Affected Products
FortiOS version 6.0.0 through 6.0.14
FortiOS version 6.4.0 through 6.4.8
FortiOS version 6.2.0 through 6.2.10
FortiOS version 7.0.0 through 7.0.3
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS.
Vulnerable version may allow an authenticated attacker to execute privileged commands on a linked FortiSwitch via diagnose system CLI commands
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-21-242
- FG-IR-21-242 -
www.fortiguard.com/psirt/FG-IR-21-242
CVEs related to QID 44046
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-242 |
|