A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4.0 through 6.4.9, FortiAP-W2 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.3, and 7.4.0 through 7.4.2, FortiAP 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.3, and 7.4.0 through 7.4.2 allow a local authenticated attacker to execute unauthorized code via the CLI.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HFortinet Fortiap
APPFortinet6.4.1 – 7.2.4 (excl.)7.4.0 – 7.4.3 (excl.)Fortinet Fortiap S
APPFortinet6.2.0 – 6.4.10 (excl.)Fortinet Fortiap W2
APPFortinet6.4.0 – 7.2.4 (excl.)7.4.0 – 7.4.3 (excl.)
Related vulnerabilities
An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the co...
An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 ...
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, Fort...
Podatność polegająca na niewłaściwej neutralizacji znaków specjalnych używanych w poleceniach systemu operacyj...
Nieuprawniona neutralizacja specjalnych znaków używanych w poleceniach systemowych ("OS Command Injection") w ...