Command Injection Vulnerability in Fortinet Products
CVE-2022-40679
7.1HIGH
What is CVE-2022-40679?
An improper neutralization of special elements used in an OS command vulnerability exists in FortiADC and FortiDDoS products, enabling authenticated attackers to execute unauthorized commands by leveraging specifically crafted arguments. This weakness affects various versions across both product lines, highlighting the importance of keeping systems updated and applying necessary patches to mitigate potential exploitation. Organizations using Fortinet's solutions should review their configurations and work towards implementing recommended security practices to protect against this vulnerability.
Affected Version(s)
FortiADC 7.1.0
FortiADC 7.0.0 <= 7.0.3
FortiADC 6.2.0 <= 6.2.4