Restricted Shell Escape via Argument Injection

Summary

An improper neutralization of special elements used in an OS command vulmerability [CWE-78] in FortiRecorder & FortiMail may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code via the CLI.

Version Affected Solution
FortiMail 7.6 Not affected Not Applicable
FortiMail 7.4 Not affected Not Applicable
FortiMail 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiMail 7.0 7.0.0 through 7.0.6 Upgrade to 7.0.7 or above
FortiMail 6.4 6.4.0 through 6.4.7 Upgrade to 6.4.8 or above
FortiRecorder 7.2 Not affected Not Applicable
FortiRecorder 7.0 7.0.0 Upgrade to 7.0.2 or above
FortiRecorder 6.4 6.4.0 through 6.4.4 Upgrade to 6.4.5 or above

Acknowledgement

This was discovered during an independent source code audit commissioned by Fortinet.

Timeline

2025-01-14: Initial publication