FG-IR-20-210: [FortiAP] OS command Injection through hidden kdbg CLI command
Published Jul 7, 2021
·Updated
An instance of improper neutralization of special elements used in an OS Command found in FortiAP's console may allow an authenticated attacker to execute unauthorized commands by running the kdbg CLI command with specifically crafted arguments.
Affected Software
1 affected component
Fortinet FortiAP
Event History
Jul 7, 2021
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 25, 2024
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-20-210?
FG-IR-20-210 is classified as a medium severity vulnerability.
2
How do I fix FG-IR-20-210?
To fix FG-IR-20-210, update your FortiAP to the latest version provided by Fortinet.
3
What type of attack does FG-IR-20-210 allow?
FG-IR-20-210 allows an authenticated attacker to execute unauthorized commands on the FortiAP console.
4
Which software is affected by FG-IR-20-210?
FG-IR-20-210 affects instances of Fortinet FortiAP.
5
What causes FG-IR-20-210?
FG-IR-20-210 is caused by improper neutralization of special elements used in an OS command.