CVE-2022-40679: OS Command Injection
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, 7.1.0; FortiDDoS 4.x all versions, 5.0 all versions, 5.1 all versions, 5.2 all versions, 5.3 all versions, 5.4 all versions, 5.5 all versions, 5.6 all versions and FortiDDoS-F 6.4.0, 6.3.0 through 6.3.3, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-40679?
CVE-2022-40679 is an improper neutralization of special elements used in an OS command vulnerability in FortiADC and FortiDDoS.
Which versions of FortiADC are affected by CVE-2022-40679?
FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, and 7.1.0 are affected by CVE-2022-40679.
Which versions of FortiDDoS are affected by CVE-2022-40679?
FortiDDoS 4.x all versions, 5.0 all versions, 5.1 all versions, 5.2 all versions, 5.3 all versions, 6.1.0 through 6.1.5, 6.2.0 through 6.2.3, and 6.3.0 through 6.3.4 are affected by CVE-2022-40679.
What is the severity of CVE-2022-40679?
CVE-2022-40679 has a severity rating of 7.8 (High).
How can I fix the CVE-2022-40679 vulnerability?
To fix the CVE-2022-40679 vulnerability, it is recommended to update FortiADC and FortiDDoS to the latest patched versions provided by Fortinet.