FG-IR-20-177: [FortiDeceptor] OS command injection
Published Jan 4, 2021
·Updated
Multiple OS command injection vulnerabilities in FortiDeceptor management interface may allow an authenticated user to execute arbitrary commands on the system via specifically crafted web requests.
Affected Software
1 affected component
Fortinet FortiDeceptor
Event History
Jan 4, 2021
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-20-177?
The severity of FG-IR-20-177 is considered high due to its impact on system security.
2
How do I fix FG-IR-20-177?
To fix FG-IR-20-177, apply the latest patches released by Fortinet for FortiDeceptor.
3
Who is affected by FG-IR-20-177?
FG-IR-20-177 affects authenticated users of the Fortinet FortiDeceptor management interface.
4
What can attackers achieve with FG-IR-20-177?
Attackers can execute arbitrary OS commands through specifically crafted web requests due to FG-IR-20-177.
5
Is authentication required to exploit FG-IR-20-177?
Yes, exploitation of FG-IR-20-177 requires authentication to the FortiDeceptor management interface.