OS Command Injection Vulnerability in Fortinet FortiIsolator
CVE-2024-54025

6.5MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
8 April 2025

Summary

An OS command injection vulnerability exists in Fortinet FortiIsolator's command-line interface (CLI) prior to version 2.4.6. This flaw allows an attacker with privileged access to execute unauthorized commands by crafting specific CLI requests. The improper handling of special elements within these commands can lead to serious security breaches, enabling the execution of malicious code that may compromise the system.

Affected Version(s)

FortiIsolator 2.4.3 <= 2.4.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.