FG-IR-24-220: OS command injection in external connector
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiAnalyzer, FortiManager, FortiAnalyzer BigData, FortiAnalyzer Cloud and FortiManager Cloud GUI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted HTTPS or HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-220?
The vulnerability FG-IR-24-220 is classified as an OS Command Injection vulnerability, allowing authenticated privileged attackers to execute unauthorized commands.
How do I fix FG-IR-24-220?
To fix FG-IR-24-220, update to the appropriate version of FortiAnalyzer, FortiManager, or their cloud counterparts as specified in the advisory.
Which products are affected by FG-IR-24-220?
FG-IR-24-220 affects various versions of FortiAnalyzer, FortiManager, FortiAnalyzer BigData, FortiAnalyzer Cloud, and FortiManager Cloud.
Who can exploit FG-IR-24-220?
The FG-IR-24-220 vulnerability can be exploited by authenticated privileged users.
What can an attacker achieve with FG-IR-24-220?
An attacker exploiting FG-IR-24-220 can execute unauthorized OS commands on the affected systems.