QID 44052

Date Published: 2023-05-31

QID 44052: FortiOS Format String Vulnerability in Command Line Interpreter (FG-IR-21-235) (Unauthenticated Check)

A format string vulnerability [CWE-134] in the command line interpreter of FortiOS may allow an authenticated user to execute unauthorized code or commands via specially crafted command arguments.

Affected Products:
FortiOS version 6.0.0 through 6.0.14
FortiOS version 6.2.0 through 6.2.10
FortiOS version 6.4.0 through 6.4.8
FortiOS version 7.0.0 through 7.0.2

QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS.

Vulnerable FortiOS may allow an authenticated user to execute unauthorized code or commands via specially crafted command arguments.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-21-235

    Vendor References

    CVEs related to QID 44052

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-235 URL Logo www.fortiguard.com/psirt/FG-IR-21-235