CVE-2021-43075: Command Injection
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the alarm dashboard and controller config handlers.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-43075?
CVE-2021-43075 is a vulnerability that allows for os command injection in Fortinet FortiWLM versions 8.6.2 and below.
How does CVE-2021-43075 affect Fortinet FortiWLM?
CVE-2021-43075 affects Fortinet FortiWLM versions 8.6.2 and below.
What is the severity of CVE-2021-43075?
CVE-2021-43075 has a severity rating of 8.8 (critical).
How can an attacker exploit CVE-2021-43075?
An attacker can exploit CVE-2021-43075 by executing unauthorized code or commands through crafted HTTP requests to Fortinet FortiWLM.
Is there a fix for CVE-2021-43075?
To fix CVE-2021-43075, users should upgrade to a version higher than 8.6.2 for Fortinet FortiWLM.