CVE-2022-33872: Command Injection
Published Oct 10, 2022
·Updated
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.
Affected Software
3 affected components
Fortinet FortiTester>=2.3.0<3.9.2
Fortinet FortiTester>=4.0.0<4.2.1
Fortinet FortiTester>=7.0.0<7.1.1
Event History
Oct 10, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-33872.
2
What is the severity of CVE-2022-33872?
The severity of CVE-2022-33872 is critical (9.8).
3
What is the CWE ID of this vulnerability?
The CWE ID of this vulnerability is CWE-78.
4
Which software versions are affected by CVE-2022-33872?
FortiTester versions 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, and 7.0.0 through 7.1.0 are affected by CVE-2022-33872.
5
How can an attacker exploit CVE-2022-33872?
An unauthenticated remote attacker can exploit CVE-2022-33872 by executing arbitrary commands through the Telnet login components of FortiTester.