HIGH🇵🇱 Wersja polska

CVE-2022-27489

CVSS 7.2v3.1pub. 2023-02-16upd. 2024-11-21

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.0.0 through 7.0.3, 5.3.2, 4.2.4 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Fortinet Fortiextender

    HW
    Fortinet
    all versions
  • Fortinet Fortiextender Firmware

    OS
    Fortinet
    3.0.03.0.13.0.23.1.03.1.15.3.24.2.0 – 4.2.5 (excl.)3.3.0 – 3.3.3 (excl.)7.0.0 – 7.0.4 (excl.)4.1.1 – 4.1.9 (excl.)3.2.1 – 3.2.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2025-64153HIGH7.2same product

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet Forti...

CVE-2024-23663HIGH8.8same product

An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0...

CVE-2022-23447HIGH7.5same product

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fo...

CVE-2021-41016HIGH7.8same product

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtende...

CVE-2025-46775MEDIUM5.5same product

A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1...