Improper Neutralization of Special Elements used in a Command in DAS component

Summary

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiClientEMS may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.

Version Affected Solution
FortiClientEMS Cloud 7.4 Not affected Not Applicable
FortiClientEMS Cloud 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiClientEMS Cloud 7.0 7.0.0 through 7.0.12 Upgrade to 7.0.13 or above
FortiClientEMS 7.4 Not affected Not Applicable
FortiClientEMS 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiClientEMS 7.0 7.0.0 through 7.0.12 Upgrade to 7.0.13 or above

Fortinet in Q2/24 has remediated this issue in FortiSASE version 24.2.c; and customers do not need to perform any action.

Acknowledgement

Fortinet is pleased to thank ANSSI for reporting this vulnerability under responsible disclosure.

Timeline

2024-09-10: Initial publication