OS Command Injection Vulnerability in FortiWAN Products

CVE-2021-26115

7.6HIGH

Key Information

Vendor
Fortinet
Status
Fortiwan
Vendor
CVE Published:
19 December 2024

Summary

CVE-2021-26115 is a high-severity OS command injection vulnerability affecting FortiWAN versions 4.5.7 and earlier. This security flaw resides in the Command Line Interface (CLI), enabling local, authenticated, and unprivileged attackers to execute specially-crafted commands. By exploiting this vulnerability, attackers can escalate their privileges to root, potentially gaining unauthorized access and control over affected systems. It is crucial for users and administrators of FortiWAN products to apply available patches and mitigate risks associated with this vulnerability. For more detailed information, refer to Fortinet's official advisory at FortiGuard.

Affected Version(s)

FortiWAN <= 4.5.7

FortiWAN <= 4.4.1

FortiWAN <= 4.3.1

Refferences

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.