OS Command Injection Vulnerability in Fortinet FortiExtender
CVE-2022-27489
7HIGH
What is CVE-2022-27489?
An OS command injection vulnerability exists in Fortinet FortiExtender versions 7.0.0 to 7.0.3, 5.3.2, and 4.2.4 and below, allowing attackers to execute unauthorized code through specially crafted HTTP requests. This vulnerability arises from improper neutralization of special elements used in OS commands, potentially leading to severe security breaches. Fortinet recommends applying the latest updates to mitigate these risks.
Affected Version(s)
FortiExtender 7.0.0 <= 7.0.3
FortiExtender 5.3.2
FortiExtender 4.2.0 <= 4.2.4