First published: Tue Sep 06 2022(Updated: )
An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiAP, FortiAP-S, FortiAP-W2 and FortiAP-U may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAP | ||
Fortinet FortiAP | ||
Fortinet FortiAP | ||
Fortinet FortiAP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-21-163 is considered critical due to the potential for unauthorized command execution.
To fix FG-IR-21-163, update the affected FortiAP devices to the latest firmware version provided by Fortinet.
FG-IR-21-163 affects users of Fortinet FortiAP, FortiAP-S, FortiAP-W2, and FortiAP-U.
FG-IR-21-163 is classified as an OS command injection vulnerability.
Yes, FG-IR-21-163 can potentially be exploited by an authenticated attacker who has access to the command line interpreter.