FG-IR-24-392: OS command injection on gen-ca-cert command
Published Apr 8, 2025
·Updated
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiIsolator CLI may allow a privileged attacker to execute unauthorized code or commands via crafted CLI requests.
Affected Software
1 affected componentFixes available
Fortinet FortiIsolator>=2.4.3<=2.4.6
Event History
Apr 8, 2025
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-24-392?
The severity of FG-IR-24-392 is high due to the potential for OS command injection allowing unauthorized code execution.
2
How do I fix FG-IR-24-392?
To fix FG-IR-24-392, upgrade FortiIsolator to version 2.4.7 or later.
3
What systems are affected by FG-IR-24-392?
FG-IR-24-392 affects FortiIsolator versions between 2.4.3 and 2.4.6.
4
What type of vulnerability is FG-IR-24-392?
FG-IR-24-392 is classified as an OS Command Injection vulnerability.
5
Who can exploit FG-IR-24-392?
A privileged attacker with knowledge of the CLI can exploit FG-IR-24-392 to execute unauthorized commands.