CVE-2022-33874: Command Injection
Published Oct 10, 2022
·Updated
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.
Affected Software
3 affected components
Fortinet FortiTester>=2.3.0<3.9.2
Fortinet FortiTester>=4.0.0<4.2.1
Fortinet FortiTester>=7.0.0<7.1.1
Event History
Oct 10, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-33874.
2
What is the severity level of CVE-2022-33874?
CVE-2022-33874 has a severity level of critical (9.8).
3
What is the CWE ID of this vulnerability?
The CWE ID of this vulnerability is CWE-78.
4
Which versions of FortiTester are affected by CVE-2022-33874?
FortiTester versions 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, and 7.0.0 through 7.1.0 are affected by CVE-2022-33874.
5
How can an attacker exploit CVE-2022-33874?
An unauthenticated remote attacker can exploit CVE-2022-33874 by executing arbitrary commands in the SSH login components of FortiTester.