CVE-2022-22301: OS Command Injection
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiAP-C console 5.4.0 through 5.4.3, 5.2.0 through 5.2.1 may allow an authenticated attacker to execute unauthorized commands by running CLI commands with specifically crafted arguments.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-22301?
CVE-2022-22301 is a vulnerability in FortiAP-C console versions 5.4.0 through 5.4.3 and 5.2.0 through 5.2.1.
How severe is CVE-2022-22301?
CVE-2022-22301 has a severity rating of 7.8, which is considered high.
How does CVE-2022-22301 impact FortiAP-C console?
CVE-2022-22301 allows an authenticated attacker to execute unauthorized commands on FortiAP-C console by running specially crafted CLI commands.
Which versions of FortiAP-C console are affected by CVE-2022-22301?
CVE-2022-22301 affects FortiAP-C console versions 5.4.0 through 5.4.3 and 5.2.0 through 5.2.1.
How can I fix CVE-2022-22301?
To fix CVE-2022-22301, apply the necessary updates or patches provided by Fortinet.