Lucene search

K
fortinetFortiGuard LabsFG-IR-21-060
HistoryApr 05, 2022 - 12:00 a.m.

FortiWAN - Pervasive OS command injection

2022-04-0500:00:00
FortiGuard Labs
www.fortiguard.com
23
fortiwan
command injection
cwe-78
web gui
http requests
authenticated attacker
os vulnerabilities

EPSS

0.001

Percentile

44.0%

Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in FortiWAN Web GUI may allow an authenticated attacker to execute arbitrary commands on the underlying system’s shell via specifically crafted HTTP requests.

EPSS

0.001

Percentile

44.0%

Related for FG-IR-21-060