CVE-2022-27483: OS command injection vulnerability in CLI
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x and FortiAnalyzer version 7.0.0 through 7.0.3, version 6.4.0 through 6.4.7, 6.2.x and 6.0.x allows attacker to execute arbitrary shell code as root user via diagnose system CLI commands.
Other sources
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiAnalyzer & FortiManager may allow an authenticated attacker to execute arbitrary shell code as root user via diagnose system CLI commands.
— FortiGuard
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-27483?
CVE-2022-27483 is a vulnerability that allows for OS command injection in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x and FortiAnalyzer version 7.0.0 through 7.0.3, version 6.4.0 through 6.4.7, 6.2.x and 6.0.x.
How severe is CVE-2022-27483?
CVE-2022-27483 has a severity score of 7.2, which is considered high.
What software is affected by CVE-2022-27483?
Fortinet FortiManager versions 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x, and FortiAnalyzer versions 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x are affected by CVE-2022-27483.
How can an attacker exploit the CVE-2022-27483 vulnerability?
An attacker can exploit the CVE-2022-27483 vulnerability by using a specially crafted input to execute arbitrary commands on the target system.
Is there a fix for CVE-2022-27483?
Yes, it is recommended to update to the latest version of Fortinet FortiManager and FortiAnalyzer to fix CVE-2022-27483.