PSIRT Advisories
FortiWeb & FortiADC - OS command injection in CLI
Summary
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiWeb & FortiADC may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
Affected Products
FortiWeb version 7.0.0 through 7.0.3FortiADC version 7.1.0 through 7.1.1
FortiADC version 7.0.0 through 7.0.3
FortiADC 6.2 all versions
FortiADC 6.1 all versions
FortiADC 6.0 all versions
FortiADC 5.4 all versions
FortiADC 5.3 all versions
FortiADC 5.2 all versions
FortiADC 5.1 all versions
Solutions
Please upgrade to FortiWeb version 7.2.0 or abovePlease upgrade to FortiWeb version 7.0.4 or above
Please upgrade to FortiADC version 7.2.0 or above
Please upgrade to FortiADC version 7.1.2 or above
Please upgrade to FortiADC version 7.0.4 or above