PT-2021-23674 · Fortinet · Fortinet Meru Ap
Published
2021-12-09
·
Updated
2021-12-13
·
CVE-2021-42759
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Fortinet Meru AP versions 8.6.1 and below
Fortinet Meru AP versions 8.5.5 and below
Description
A violation of secure design principles allows an attacker to execute unauthorized code or commands via crafted cli commands.
Recommendations
For Fortinet Meru AP versions 8.6.1 and below, update to a version above 8.6.1 to resolve the issue.
For Fortinet Meru AP versions 8.5.5 and below, update to a version above 8.5.5 to resolve the issue.
As a temporary workaround, consider restricting access to cli commands until a patch is available.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortinet Meru Ap