PT-2022-17686 · Fortinet · Fortiadc

Published

2022-07-18

·

Updated

2022-07-25

·

CVE-2022-26120

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiADC versions 5.0.0 through 6.2.2 FortiADC versions 7.0.0 through 7.0.1
Description The issue is related to improper neutralization of special elements used in an SQL Command, also known as SQL Injection. This may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Recommendations For FortiADC versions 5.0.0 through 6.2.2, update to a version that includes the fix for this issue. For FortiADC versions 7.0.0 through 7.0.1, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the management interface to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26120

Affected Products

Fortiadc