PT-2022-6076 · Fortinet · Fortitester
Published
2022-10-10
·
Updated
2022-10-20
·
CVE-2022-35844
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FortiTester versions 2.3.0 through 3.9.1
FortiTester versions 4.0.0 through 4.2.0
FortiTester versions 7.0.0 through 7.1.0
Description
The issue exists due to the failure to neutralize special elements used in an OS command, allowing an authenticated attacker to execute unauthorized commands via specifically crafted arguments to commands of the
certificate import feature. This can be done by exploiting the management interface of FortiTester.Recommendations
For FortiTester versions 2.3.0 through 3.9.1, update to a version outside of this range to mitigate the risk.
For FortiTester versions 4.0.0 through 4.2.0, update to a version outside of this range to mitigate the risk.
For FortiTester versions 7.0.0 through 7.1.0, update to a version outside of this range to mitigate the risk.
As a temporary workaround, consider restricting access to the
certificate import feature until a patch is available.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortitester