CVE-2022-27489: OS Command Injection
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.0.0 through 7.0.3, 5.3.2, 4.2.4 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-27489?
CVE-2022-27489 is considered a high severity vulnerability due to its potential for code execution by unauthorized attackers.
How do I fix CVE-2022-27489?
To fix CVE-2022-27489, upgrade your Fortinet FortiExtender firmware to a patched version provided by Fortinet.
What systems are affected by CVE-2022-27489?
CVE-2022-27489 affects Fortinet FortiExtender firmware versions 7.0.0 through 7.0.3, 5.3.2, and 4.2.4 and below.
What kind of attacks can be executed through CVE-2022-27489?
CVE-2022-27489 allows attackers to perform OS command injection, enabling them to execute unauthorized commands via crafted HTTP requests.
Is there a workaround for CVE-2022-27489?
A recommended workaround for CVE-2022-27489 is to implement strict input validation rules to mitigate unauthorized command execution.