Multiple command injections on CLI

Summary

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in FortiIsolator may allow an authenticated attacker with at least read-only admin permission and CLI access to execute unauthorized code via specifically crafted CLI commands.

Version Affected Solution
FortiIsolator 2.4 2.4.0 through 2.4.5 Upgrade to 2.4.6 or above
FortiIsolator 2.3 Not affected Not Applicable
FortiIsolator 2.2 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Adham El karn of Fortinet Product Security team.

Timeline

2025-03-11: Initial publication