First published: Tue Nov 02 2021(Updated: )
A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWLM | >=8.2.2<=8.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-36185.
The severity of CVE-2021-36185 is high with a CVSS score of 8.8.
The affected software for CVE-2021-36185 is Fortinet FortiWLM version 8.6.1 and below.
CVE-2021-36185 allows an attacker to execute unauthorized code or commands via crafted HTTP requests.
It is recommended to update Fortinet FortiWLM to a version above 8.6.1 to mitigate CVE-2021-36185.