PT-2020-6668 · Fortinet · Fortiap-S/W2+1

Published

2020-05-25

·

Updated

2020-06-03

·

CVE-2019-15709

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiAP-S/W2 versions 6.0.5 and below, 6.2.0 through 6.2.2 FortiAP-U version 6.0.1 and below
Description The issue arises from insufficient input validation in the CLI admin console of Fortinet FortiAP-S/W2 and FortiAP, allowing a remote attacker to overwrite system files using specially crafted tcpdump commands in the CLI.
Recommendations For FortiAP-S/W2 versions 6.0.5 and below, update to a version above 6.0.5 to resolve the issue. For FortiAP-S/W2 versions 6.2.0 through 6.2.2, update to a version above 6.2.2 to resolve the issue. For FortiAP-U version 6.0.1 and below, update to a version above 6.0.1 to resolve the issue. As a temporary workaround, consider restricting access to the CLI admin console to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03303
CVE-2019-15709

Affected Products

Fortiap-S/W2
Fortiap-U