First published: Tue Apr 11 2023(Updated: )
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, 7.1.0; FortiDDoS 4.x all versions, 5.0 all versions, 5.1 all versions, 5.2 all versions, 5.3 all versions, 5.4 all versions, 5.5 all versions, 5.6 all versions and FortiDDoS-F 6.4.0, 6.3.0 through 6.3.3, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiADC | >=5.0.0<6.2.5 | |
Fortinet FortiDDoS | >=4.0.0<5.7.0 | |
Fortinet FortiDDoS-F | >=6.1.0<6.1.5 | |
Fortinet FortiDDoS-F | >=6.2.0<6.2.3 | |
Fortinet FortiDDoS-F | >=6.3.0<6.3.4 | |
Fortinet FortiDDoS-F | =6.4.0 |
Please upgrade to FortiDDoS-F version 6.4.1 or above Please upgrade to FortiDDoS-F version 6.3.4 or above Please upgrade to FortiDDoS-F version 6.2.3 or above Please upgrade to FortiDDoS-F version 6.1.5 or above Please upgrade to FortiDDoS version 5.7.0 or above Please upgrade to FortiADC version 7.1.1 or above Please upgrade to FortiADC version 7.0.4 or above Please upgrade to FortiADC version 6.2.5 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40679 is an improper neutralization of special elements used in an OS command vulnerability in FortiADC and FortiDDoS.
FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, and 7.1.0 are affected by CVE-2022-40679.
FortiDDoS 4.x all versions, 5.0 all versions, 5.1 all versions, 5.2 all versions, 5.3 all versions, 6.1.0 through 6.1.5, 6.2.0 through 6.2.3, and 6.3.0 through 6.3.4 are affected by CVE-2022-40679.
CVE-2022-40679 has a severity rating of 7.8 (High).
To fix the CVE-2022-40679 vulnerability, it is recommended to update FortiADC and FortiDDoS to the latest patched versions provided by Fortinet.