OS Command Injection Vulnerabilities in FortiManager and FortiAnalyzer
CVE-2021-26104
Key Information:
- Vendor
- Fortinet
- Vendor
- CVE Published:
- 6 April 2022
Summary
Multiple vulnerabilities exist within the command line interface of FortiManager, FortiAnalyzer, and FortiPortal. These vulnerabilities allow a local authenticated and unprivileged user the ability to craft specific command line parameters, thereby executing arbitrary shell commands with root privileges. This issue can lead to significant security risks, including unauthorized access and potential system compromise.
Affected Version(s)
Fortinet FortiManager, FortiAnalyzer, FortiPortal FortiManager 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, FortiAnalyzer 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, and FortiPortal 5.2.5 and below, 5.3.5 and below and 6.0.4 and below
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved