An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via the FortiSwitch CLI.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HFortinet Fortiswitch
OSFortinet7.4.06.0.0 – 6.2.8 (excl.)6.4.0 – 6.4.14 (excl.)7.0.0 – 7.0.8 (excl.)7.2.0 – 7.2.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References
Related vulnerabilities
CVE-2024-48887CRITICAL9.8PL ✓same product
Fortinet FortiSwitch — nieautoryzowana zmiana hasła administratora (RCE-ready)
CVE-2023-25610CRITICAL9.8PL ✓same product
Buffer Underflow w interfejsie administracyjnym Fortinet FortiOS / FortiProxy — RCE bez uwierzytelnienia
CVE-2023-37936CRITICAL9.8PL ✓same product
Fortinet FortiSwitch — użycie zakodowanego klucza kryptograficznego umożliwia RCE
CVE-2016-4573CRITICAL9.8PL ✓same product
Fortinet FortiSwitch — pominięcie uwierzytelnienia konta rest_admin
CVE-2016-6909CRITICAL9.8PL ✓same product
Buffer overflow w parserze Cookie w Fortinet FortiOS/FortiSwitch — RCE