Aller au contenu

Fiche vulnérabilité

CVE-2022-39947 : faille élevée Fortinet FortiADC (CVSS 8.6)

Description

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiADC version 6.2.0 through 6.2.3, FortiADC version version 6.1.0 through 6.1.6, FortiADC version 6.0.0 through 6.0.4, FortiADC version 5.4.0 through 5.4.5 may allow an attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

En bref

Sévérité
Élevée (CVSS 8.6)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C
Exploitation active
Non signalée par la CISA
Publication
3 janv. 2023
Dernière mise à jour
23 oct. 2024

Produits concernés

  • Fortinet FortiADC

Correctif et mesures

Please upgrade to uptoming FortiADC 7.0.2. Please upgrade to upcoming FortiADC 6.2.4.

Références

Rechercher une autre vulnérabilité dans la base CVE