FG-IR-22-120: FortiAP's - Arbitrary file read through the CLI
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP, FortiAP-W2, FortiAP-U, FortiAP-C may allow an authenticated attacker to read arbitrary files via specially crafted command arguments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-22-120?
The FG-IR-22-120 vulnerability has been identified as a risk due to improper filtering, allowing attackers to potentially read arbitrary files.
How do I fix FG-IR-22-120?
To mitigate FG-IR-22-120, upgrade to FortiAP versions 7.2.2 or above, or 7.0.6 or above for affected models.
Which FortiAP versions are affected by FG-IR-22-120?
FG-IR-22-120 affects FortiAP versions ranging from 7.2.0 to 7.2.1, 7.0.0 to 7.0.5, as well as earlier unsupported versions.
Can FG-IR-22-120 be exploited remotely?
FG-IR-22-120 requires authentication from an attacker, limiting its exploitability to authenticated users only.
What type of vulnerability is FG-IR-22-120?
FG-IR-22-120 is categorized as an incomplete filtering vulnerability, specifically related to command line arguments.