QID 44110
Date Published: 2023-10-30
QID 44110: FortiGate Execute Unauthorized Code or Commands Vulnerability (FG-IR-21-091)
A debug functionality in FortiGate may allow a privileged user to execute unauthorized code or commands via specific chains of `print str` and `cmd mem` cli commands to, respectively, read and write hexadecimal values to any memory address.
Affected Products
FortiGate version 7.0.0
FortiGate version 6.4.6 and below
FortiGate version 6.2.9 and below
FortiGate 6.0 all versions
FortiGate 5.6 al versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of this vulnerability may expose sensitive information to an authenticate attacker.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-21-091
Vendor References
- FG-IR-21-091 -
www.fortiguard.com/psirt/FG-IR-21-091
CVEs related to QID 44110
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-091 |
|