FG-IR-24-397: OS command injection on diagnose feature (GUI)
Published Apr 8, 2025
·Updated
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiIsolator may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code via specifically crafted HTTP requests.
Affected Software
1 affected componentFixes available
Fortinet FortiIsolator>=2.4.3<=2.4.6
Event History
Apr 8, 2025
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-24-397?
The severity of FG-IR-24-397 is critical due to its potential for OS command injection by privileged attackers.
2
How do I fix FG-IR-24-397?
To fix FG-IR-24-397, upgrade FortiIsolator to version 2.4.7 or later.
3
What versions of FortiIsolator are affected by FG-IR-24-397?
FortiIsolator versions 2.4.3 to 2.4.6 are affected by FG-IR-24-397.
4
Who can exploit the vulnerability FG-IR-24-397?
Only a privileged attacker with a super-admin profile and CLI access can exploit FG-IR-24-397.
5
What type of vulnerability is FG-IR-24-397?
FG-IR-24-397 is categorized as an OS Command Injection vulnerability (CWE-78).