FG-IR-24-124: OS command injection in CLI command
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in FortiManager CLI may allow a privileged attacker to execute unauthorized code or commands via crafted CLI requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-124?
The severity of FG-IR-24-124 is considered high due to the potential for unauthorized code execution.
How do I fix FG-IR-24-124?
To fix FG-IR-24-124, upgrade FortiManager and FortiAnalyzer to the latest versions provided in the security advisory.
Who is affected by FG-IR-24-124?
FG-IR-24-124 affects multiple versions of FortiManager and FortiAnalyzer prior to the recommended patched versions.
Can FG-IR-24-124 be exploited remotely?
Yes, FG-IR-24-124 can be exploited by an attacker with privileged access remotely via crafted CLI requests.
What type of vulnerability is FG-IR-24-124?
FG-IR-24-124 is classified as an OS Command Injection vulnerability that involves improper neutralization of special elements.