CVE-2022-35849: OS Command Injection
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 through 7.1.1, 7.0.0 through 7.0.3, 6.2.0 through 6.2.5 and 6.1.0 all versions may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2022-35849.
What is the severity of CVE-2022-35849?
The severity of CVE-2022-35849 is high with a severity value of 8.8.
Which software versions are affected by CVE-2022-35849?
FortiADC versions 7.1.0 through 7.1.1, 7.0.0 through 7.0.3, 6.2.0 through 6.2.5 are affected by CVE-2022-35849.
How can an attacker exploit CVE-2022-35849?
An authenticated attacker can execute unauthorized commands via specific means in the management interface of FortiADC.
Is there a fix available for CVE-2022-35849?
Yes, upgrading FortiADC to a version beyond the affected range will fix the vulnerability.