FG-IR-24-116: OS command injection in CLI command
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData CLI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-116?
The FG-IR-24-116 vulnerability has a high severity due to its potential for OS command injection by an authenticated privileged attacker.
How do I fix FG-IR-24-116?
To remediate the FG-IR-24-116 vulnerability, update your FortiAnalyzer or FortiManager software to the recommended versions provided by Fortinet.
Which products are affected by FG-IR-24-116?
The FG-IR-24-116 vulnerability affects FortiManager and FortiAnalyzer, particularly versions below the specified remedial versions.
Can FG-IR-24-116 be exploited remotely?
FG-IR-24-116 requires authentication, thus it can only be exploited by an authenticated privileged user with access to the affected systems.
What are the consequences of an exploit of FG-IR-24-116?
Exploitation of the FG-IR-24-116 vulnerability could allow an attacker to execute unauthorized commands on the affected system, leading to potential data breaches or system compromise.