PT-2020-6668 · Fortinet · Fortiap-S/W2+1
Published
2020-05-25
·
Updated
2020-06-03
·
CVE-2019-15709
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FortiAP-S/W2 versions 6.0.5 and below, 6.2.0 through 6.2.2
FortiAP-U version 6.0.1 and below
Description
The issue arises from insufficient input validation in the CLI admin console of Fortinet FortiAP-S/W2 and FortiAP, allowing a remote attacker to overwrite system files using specially crafted
tcpdump commands in the CLI.Recommendations
For FortiAP-S/W2 versions 6.0.5 and below, update to a version above 6.0.5 to resolve the issue.
For FortiAP-S/W2 versions 6.2.0 through 6.2.2, update to a version above 6.2.2 to resolve the issue.
For FortiAP-U version 6.0.1 and below, update to a version above 6.0.1 to resolve the issue.
As a temporary workaround, consider restricting access to the CLI admin console to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiap-S/W2
Fortiap-U