First published: Thu Oct 26 2017(Updated: )
An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file management AP script download webUI page allows an authenticated admin user to execute arbitrary system console commands via crafted HTTP requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWLC | >=6.1-2<=6.1-5 | |
Fortinet FortiWLC | >=7.0-7<=7.0-10 | |
Fortinet FortiWLC | >=8.0<=8.2 | |
Fortinet FortiWLC | >=8.3.0<=8.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.