FG-IR-24-425: OS command injection
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager may allow an authenticated remote attacker to execute unauthorized code via FGFM crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-425?
The FG-IR-24-425 vulnerability is rated as critical due to its potential for OS Command Injection.
How do I fix FG-IR-24-425?
To remediate FG-IR-24-425, update FortiManager to a version that includes the fix, such as versions 7.6.1 or 7.4.5 and above.
Who is affected by FG-IR-24-425?
FG-IR-24-425 affects FortiManager versions 7.0.1 through 7.4.4 and earlier versions of FortiManager.
Can FG-IR-24-425 be exploited remotely?
Yes, FG-IR-24-425 allows an authenticated remote attacker to exploit the vulnerability via crafted FGFM requests.
What type of vulnerability is FG-IR-24-425?
FG-IR-24-425 is classified as an OS Command Injection vulnerability specifically identified as CWE-78.