QID 730161
QID 730161: Fortinet FortiWeb OS Command Injection Vulnerability
FortiWeb is a web application firewall (WAF) that protects web applications and APIs from attacks that target known and unknown exploits and helps maintain compliance with regulations.
QID Detection Logic(Unauthenticated):
Check Fortinet FortiWeb version 6.3.11 and prior
An OS command injection vulnerability in FortiWeb's management interface may allow a remote authenticated attacker to execute arbitrary commands on the system via the SAML server configuration page.
Solution
There is no official patch available from Fortinet at this point in time
Workaround:
Users should "disable the FortiWeb device's management interface from untrusted networks, which would include the internet."
Vendor References
CVEs related to QID 730161
Software Advisories
| Advisory ID | Software | Component | Link |
|---|