OS Command Injection Vulnerability in FortiTester by Fortinet
CVE-2023-36642

7.8HIGH

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
13 September 2023

Summary

The vulnerability in FortiTester affects versions from 3.0.0 through 7.2.3, allowing authenticated attackers to exploit improper neutralization of special elements used in OS commands. By crafting specific arguments to existing commands, attackers can execute unauthorized commands through the management interface, posing a threat to the integrity and security of the system. This highlights the critical need for timely patches and security measures to mitigate risks associated with command injection attacks.

Affected Version(s)

FortiTester 7.2.0 <= 7.2.3

FortiTester 7.1.0 <= 7.1.1

FortiTester 7.0.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.