First published: Wed Apr 06 2022(Updated: )
An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAuthenticator | >=5.0.0<6.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-26116.
The severity of CVE-2021-26116 is high with a CVSS score of 8.8.
CVE-2021-26116 allows an authenticated attacker to execute unauthorized commands in FortiAuthenticator before version 6.3.1.
An attacker can exploit CVE-2021-26116 by supplying specially crafted arguments to existing commands in FortiAuthenticator.
Yes, the fix for CVE-2021-26116 is available in FortiAuthenticator version 6.3.1 or later.