Command Injection Vulnerability in FortiADC Management Interface
CVE-2022-35849
7.4HIGH
Summary
FortiADC's management interface is susceptible to a command injection vulnerability that can be exploited by an authenticated attacker. By crafting specific arguments to existing commands, attackers may execute unauthorized commands, potentially compromising the integrity and availability of the affected system. This vulnerability impacts multiple versions of FortiADC, making it crucial for administrators to take immediate action to mitigate the risks.
Affected Version(s)
FortiADC 7.1.0
FortiADC 7.0.0 <= 7.0.2
FortiADC 6.2.0 <= 6.2.4
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved