CVE-2022-27482: OS Command Injection
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.1, 6.2.0 through 6.2.2, 6.1.0 through 6.1.6, 6.0.x, 5.x.x allows attacker to execute arbitrary shell code as root via CLI commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-27482?
CVE-2022-27482 is a vulnerability in Fortinet FortiADC that allows an attacker to execute arbitrary shell code as root via CLI commands.
Which versions of Fortinet FortiADC are affected?
Fortinet FortiADC versions 7.0.0 through 7.0.1, 6.2.0 through 6.2.2, 6.1.0 through 6.1.6, 6.0.x, 5.x.x are affected.
What is the severity of CVE-2022-27482?
The severity of CVE-2022-27482 is high with a CVSS score of 7.8.
How can an attacker exploit CVE-2022-27482?
An attacker can exploit CVE-2022-27482 by exploiting a command injection vulnerability in Fortinet FortiADC to execute arbitrary shell code as root via CLI commands.
Is there a fix for CVE-2022-27482?
Yes, it is recommended to update to a patched version of Fortinet FortiADC to mitigate CVE-2022-27482.