First published: Wed Apr 06 2022(Updated: )
Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow an authenticated attacker to execute arbitrary commands on the underlying system's shell via specifically crafted HTTP requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWan | <=4.5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2021-24009 vulnerability involves multiple improper neutralization of special elements used in an OS command in FortiWAN's Web GUI before version 4.5.9, allowing an attacker to execute arbitrary commands via crafted HTTP requests.
The severity of CVE-2021-24009 is rated as critical with a CVSS score of 8.8.
Fortinet FortiWan versions up to and including 4.5.8 are affected by CVE-2021-24009.
An authenticated attacker can exploit CVE-2021-24009 by sending crafted HTTP requests to the Web GUI of FortiWAN before version 4.5.9 to execute arbitrary commands on the system's shell.