Multiple Command Injections in webserver

Summary

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the webserver of FortiNAC may allow a privileged attacker to execute arbitrary OS commands via specially crafted input parameters.

Version Affected Solution
FortiNAC 9.4 9.4.0 Upgrade to 9.4.1 or above
FortiNAC 9.2 9.2.0 through 9.2.5 Upgrade to 9.2.6 or above
FortiNAC 9.1 9.1.0 through 9.1.7 Upgrade to 9.1.8 or above
FortiNAC 8.8 8.8 all versions Migrate to a fixed release
FortiNAC 8.7 8.7 all versions Migrate to a fixed release
FortiNAC 8.6 8.6 all versions Migrate to a fixed release
FortiNAC 8.5 8.5 all versions Migrate to a fixed release
FortiNAC 8.3 8.3 all versions Migrate to a fixed release
FortiNAC 7.2 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team.

Timeline

2023-02-16: Initial publication