FG-IR-24-222: Command injection in csfd daemon
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiManager csfd daemon may allow an authenticated attacker to execute unauthorized commands via specifically crafted packets
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-222?
The FG-IR-24-222 vulnerability has been classified with a high severity due to the potential for unauthorized command execution.
How do I fix FG-IR-24-222?
To address the FG-IR-24-222 vulnerability, upgrade FortiManager or FortiManager Cloud to version 7.4.4 or later.
Who is affected by FG-IR-24-222?
The FG-IR-24-222 vulnerability affects users of FortiManager and FortiManager Cloud versions 7.4.1 to 7.4.3.
Can FG-IR-24-222 be exploited remotely?
Yes, FG-IR-24-222 can be exploited by an authenticated attacker remotely via specially crafted packets.
What type of vulnerability is FG-IR-24-222?
FG-IR-24-222 is categorized as an improper neutralization of special elements used in an OS command vulnerability.