FG-IR-21-148: Arbitrary command execution because of missing CLI input sanitization
Published Feb 1, 2022
·Updated
An improper neutralization of special elements used in a command vulnerability ('Command Injection') [CWE-77] in FortiExtender may allow an authenticated user to raise its privileges to admin user via crafted arguments of the execute CLI command.
Affected Software
1 affected component
Fortinet FortiExtender
Event History
Feb 1, 2022
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 25, 2024
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-21-148?
The severity of FG-IR-21-148 is high due to its potential to allow privilege escalation for authenticated users.
2
How do I fix FG-IR-21-148?
To fix FG-IR-21-148, it is recommended to update FortiExtender to the latest firmware version provided by Fortinet.
3
Who is affected by FG-IR-21-148?
All authenticated users of FortiExtender are potentially affected by FG-IR-21-148.
4
What type of vulnerability is FG-IR-21-148?
FG-IR-21-148 is classified as a command injection vulnerability.
5
What can FG-IR-21-148 allow an attacker to do?
FG-IR-21-148 can allow an authenticated attacker to escalate their privileges to that of an admin user.