First published: Tue Apr 08 2025(Updated: )
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiIsolator CLI may allow a privileged attacker to execute unauthorized code or commands via crafted CLI requests.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiIsolator | >=2.4.3<=2.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-24-392 is high due to the potential for OS command injection allowing unauthorized code execution.
To fix FG-IR-24-392, upgrade FortiIsolator to version 2.4.7 or later.
FG-IR-24-392 affects FortiIsolator versions between 2.4.3 and 2.4.6.
FG-IR-24-392 is classified as an OS Command Injection vulnerability.
A privileged attacker with knowledge of the CLI can exploit FG-IR-24-392 to execute unauthorized commands.