First published: Wed Sep 13 2023(Updated: )
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP, FortiAP-W2, FortiAP-U, FortiAP-C may allow an authenticated attacker to read arbitrary files via specially crafted command arguments.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAP | >=7.2.0<=7.2.1 | |
Fortinet FortiAP | >=7.0.0<=7.0.5 | |
Fortinet FortiAP | >=6.4 | |
Fortinet FortiAP | >=6.0 | |
Fortinet FortiAP-C | >=5.4.0<=5.4.4 | |
Fortinet FortiAP-C | >=5.2 | |
Fortinet FortiAP-U | =. | |
Fortinet FortiAP-U | >=6.2.0<=6.2.5 | |
Fortinet FortiAP-U | >=6.0 | |
Fortinet FortiAP-U | >=5.4 | |
Fortinet FortiAP-W2 | >=7.2.0<=7.2.1 | |
Fortinet FortiAP-W2 | >=7.0.3<=7.0.5 | |
Fortinet FortiAP-W2 | >=7.0.0<=7.0.1 | |
Fortinet FortiAP-W2 | >=6.4 | |
Fortinet FortiAP-W2 | >=6.2 | |
Fortinet FortiAP-W2 | >=6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The FG-IR-22-120 vulnerability has been identified as a risk due to improper filtering, allowing attackers to potentially read arbitrary files.
To mitigate FG-IR-22-120, upgrade to FortiAP versions 7.2.2 or above, or 7.0.6 or above for affected models.
FG-IR-22-120 affects FortiAP versions ranging from 7.2.0 to 7.2.1, 7.0.0 to 7.0.5, as well as earlier unsupported versions.
FG-IR-22-120 requires authentication from an attacker, limiting its exploitability to authenticated users only.
FG-IR-22-120 is categorized as an incomplete filtering vulnerability, specifically related to command line arguments.