OS command injection in CLI commands

Summary

An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiIsolator may allow a privileged attacker to execute arbitrary OS commands in the underlying shell via specially crafted input parameters.

Affected Products

FortiIsolator version 1.0.0
FortiIsolator version 1.1.0
FortiIsolator version 1.2.0 through 1.2.2
FortiIsolator version 2.0.0 through 2.0.1
FortiIsolator version 2.1.0 through 2.1.2
FortiIsolator version 2.2.0
FortiIsolator version 2.3.0 through 2.3.4

Solutions

Upgrade to FortiIsolator version 2.4.0 or above.

Acknowledgement

Internally discovered and reported by Mattia Fecit of Fortinet Product Security team.

Timeline

2023-10-10: Initial publication