A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x and FortiAnalyzer version 7.0.0 through 7.0.3, version 6.4.0 through 6.4.7, 6.2.x and 6.0.x allows attacker to execute arbitrary shell code as `root` user via `diagnose system` CLI commands.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-049 |
|
History
Fri, 25 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published: 2022-07-18T16:40:20
Updated: 2024-10-25T13:30:52.271Z
Reserved: 2022-03-21T00:00:00
Link: CVE-2022-27483
Updated: 2024-08-03T05:32:57.798Z
Status : Modified
Published: 2022-07-19T14:15:08.500
Modified: 2024-11-21T06:55:48.880
Link: CVE-2022-27483
No data.