CVE-2022-22298: OS Command Injection
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiIsolator version 1.0.0, FortiIsolator version 1.1.0, FortiIsolator version 1.2.0 through 1.2.2, FortiIsolator version 2.0.0 through 2.0.1, FortiIsolator version 2.1.0 through 2.1.2, FortiIsolator version 2.2.0, FortiIsolator version 2.3.0 through 2.3.4 allows attacker to execute arbitrary OS commands in the underlying shell via specially crafted input parameters.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-22298?
CVE-2022-22298 refers to the improper neutralization of special elements used in an os command (os command injection) vulnerability in Fortinet FortiIsolator.
Which versions of Fortinet FortiIsolator are affected?
Versions 1.0.0 through 1.2.2 and versions 2.0.0 through 2.1.2 of Fortinet FortiIsolator are affected.
What is the severity rating of CVE-2022-22298?
CVE-2022-22298 has a severity rating of 7.8 (High).
How does CVE-2022-22298 affect Fortinet FortiIsolator?
CVE-2022-22298 allows for improper neutralization of special elements in an os command, which could lead to os command injection in Fortinet FortiIsolator.
How can I mitigate the CVE-2022-22298 vulnerability?
To mitigate the CVE-2022-22298 vulnerability, it is recommended to update Fortinet FortiIsolator to version 2.2.0 or a later version.