CVE-2022-29061: Command Injection
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29061?
CVE-2022-29061 is classified as a high severity vulnerability due to the potential for unauthorized code execution.
How do I fix CVE-2022-29061?
To mitigate CVE-2022-29061, upgrade Fortinet FortiSOAR to version 7.2.1 or above.
Who is affected by CVE-2022-29061?
CVE-2022-29061 affects authenticated users of Fortinet FortiSOAR versions 6.4.1 to 6.4.4, 7.0.0 to 7.0.3, and 7.2.0.
What type of vulnerability is CVE-2022-29061?
CVE-2022-29061 is an OS command injection vulnerability that allows attackers to execute unauthorized commands.
What are the potential impacts of CVE-2022-29061?
Successful exploitation of CVE-2022-29061 could lead to unauthorized access and control over the affected FortiSOAR system.