OS Command Injection Vulnerability in FortiTester by Fortinet
CVE-2023-36642
7.8HIGH
Summary
The vulnerability in FortiTester affects versions from 3.0.0 through 7.2.3, allowing authenticated attackers to exploit improper neutralization of special elements used in OS commands. By crafting specific arguments to existing commands, attackers can execute unauthorized commands through the management interface, posing a threat to the integrity and security of the system. This highlights the critical need for timely patches and security measures to mitigate risks associated with command injection attacks.
Affected Version(s)
FortiTester 7.2.0 <= 7.2.3
FortiTester 7.1.0 <= 7.1.1
FortiTester 7.0.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved