CVE-2022-35844: OS Command Injection
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to commands of the certificate import feature.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35844?
CVE-2022-35844 is an improper neutralization of special elements used in an OS command vulnerability in the management interface of FortiTester.
What is the severity of CVE-2022-35844?
CVE-2022-35844 has a severity rating of 7.2 (high).
Which software versions are affected by CVE-2022-35844?
The affected software versions for CVE-2022-35844 are FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, and 7.0.0 through 7.1.0.
How can an authenticated attacker exploit CVE-2022-35844?
An authenticated attacker can exploit CVE-2022-35844 by executing unauthorized commands via specifically crafted arguments.
Where can I find more information about CVE-2022-35844?
More information about CVE-2022-35844 can be found at this reference: https://fortiguard.com/psirt/FG-IR-22-247