CVE-2021-36185: Command Injection
Published Nov 2, 2021
·Updated
A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.
Affected Software
1 affected component
Fortinet FortiWLM>=8.2.2<=8.6.1
Event History
Nov 2, 2021
CVE Published
via MITRE·06:45 PM
Data Sourced
via MITRE·06:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-36185.
2
What is the severity of CVE-2021-36185?
The severity of CVE-2021-36185 is high with a CVSS score of 8.8.
3
What is the affected software for CVE-2021-36185?
The affected software for CVE-2021-36185 is Fortinet FortiWLM version 8.6.1 and below.
4
What is the risk of CVE-2021-36185?
CVE-2021-36185 allows an attacker to execute unauthorized code or commands via crafted HTTP requests.
5
Are there any fixes or patches available for CVE-2021-36185?
It is recommended to update Fortinet FortiWLM to a version above 8.6.1 to mitigate CVE-2021-36185.