PT-2022-21878 · Fortinet · Fortiadc
Published
2022-12-06
·
Updated
2022-12-08
·
CVE-2022-33875
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiADC versions 6.2.4 and below
Fortinet FortiADC versions 7.0.0 through 7.0.2
Fortinet FortiADC version 7.1.0
Description
An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability allows an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Recommendations
For Fortinet FortiADC versions 6.2.4 and below, update to a version above 6.2.4 to mitigate the risk.
For Fortinet FortiADC versions 7.0.0 through 7.0.2, update to a version above 7.0.2 to mitigate the risk.
For Fortinet FortiADC version 7.1.0, update to a version above 7.1.0 to mitigate the risk.
As a temporary workaround, consider restricting access to the SQL command interface until a patch is available.
Avoid using specifically crafted HTTP requests in the affected API endpoints until the issue is resolved.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiadc