CVE-2016-4965: OS Command Injection
Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup functionality to execute arbitrary commands with root privileges via the graph parameter to diagnosiscontrol.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4965?
CVE-2016-4965 is classified as a high-severity vulnerability due to the potential for remote authenticated users to execute arbitrary commands with root privileges.
How do I fix CVE-2016-4965?
To fix CVE-2016-4965, upgrade Fortinet FortiWan to version 4.2.5 or later where the vulnerability has been addressed.
Who is affected by CVE-2016-4965?
CVE-2016-4965 affects Fortinet FortiWan versions prior to 4.2.5, allowing remote authenticated users to exploit the nslookup functionality.
What are the consequences of CVE-2016-4965 exploitation?
Exploitation of CVE-2016-4965 allows attackers to execute arbitrary commands as a root user, potentially compromising the entire system.
Is there a workaround for CVE-2016-4965 until I can apply the fix?
A potential workaround to mitigate CVE-2016-4965 is to limit access to the nslookup functionality for remote authenticated users.