Lucene search

K
fortinetFortiGuard LabsFG-IR-21-148
HistoryFeb 01, 2022 - 12:00 a.m.

FortiExtender - Arbitrary command execution because of missing CLI input sanitization

2022-02-0100:00:00
FortiGuard Labs
www.fortiguard.com
17
fortiextender
command injection
cli
vulnerability

EPSS

0.001

Percentile

51.1%

An improper neutralization of special elements used in a command vulnerability (‘Command Injection’) [CWE-77] in FortiExtender may allow an authenticated user to raise its privileges to admin user via crafted arguments of the execute CLI command.

EPSS

0.001

Percentile

51.1%

Related for FG-IR-21-148