CVE-2022-35845: OS Command Injection
Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.0 all versions, 4.0.0 through 4.2.0, 2.3.0 through 3.9.1 may allow an authenticated attacker to execute arbitrary commands in the underlying shell.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is CVE-2022-35845?
CVE-2022-35845 refers to multiple OS Command Injection vulnerabilities in FortiTester.
What is the severity of CVE-2022-35845?
CVE-2022-35845 has a severity score of 8.8, which is considered high.
What software versions are affected by CVE-2022-35845?
FortiTester versions 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, and 7.0.0 and 7.1.0 are affected by CVE-2022-35845.
How can an attacker exploit CVE-2022-35845?
An authenticated attacker may execute arbitrary commands in the underlying shell through the OS Command Injection vulnerabilities in FortiTester.
Is there a fix available for CVE-2022-35845?
To mitigate the vulnerabilities, Fortinet recommends upgrading to a non-vulnerable version of FortiTester.