<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Multiple command injection vulnerabilities in webserver</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-22-048</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2023-02-16T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2023-02-16T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2023-02-16T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the webserver of FortiExtender may allow a privileged attacker to execute arbitrary OS commands via specially crafted input parameters.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Execute unauthorized code or commands
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiExtender 7.2 all versions are not affectedFortiExtender version 7.0.0 through 7.0.3FortiExtender 5.3 all versionsFortiExtender version 4.2.0 through 4.2.4FortiExtender version 4.1.1 through 4.1.8FortiExtender version 4.0.0 through 4.0.2FortiExtender version 3.3.0 through 3.3.2FortiExtender version 3.2.1 through 3.2.3FortiExtender 3.1 all versionsFortiExtender 3.0 all versionsFortiExtender 0.4 all versions are not affected
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Upgrade to FortiExtender version 7.2.0 and aboveUpgrade to FortiExtender version 7.0.4 and aboveUpgrade to FortiExtender version 4.2.5 and aboveUpgrade to FortiExtender upcoming version 4.1.9 and aboveUpgrade to FortiExtender upcoming version 4.0.3 and aboveUpgrade to FortiExtender version 3.3.3 and aboveUpgrade to FortiExtender version 3.2.4 and above
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiExtender" Type="Product Name">
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-7.0.3">FortiExtender 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-7.0.2">FortiExtender 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-7.0.1">FortiExtender 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-7.0.0">FortiExtender 7.0.0</FullProductName>
                </Branch>
                <Branch Name="5.3.2" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-5.3.2">FortiExtender 5.3.2</FullProductName>
                </Branch>
                <Branch Name="4.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.2.4">FortiExtender 4.2.4</FullProductName>
                </Branch>
                <Branch Name="4.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.2.3">FortiExtender 4.2.3</FullProductName>
                </Branch>
                <Branch Name="4.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.2.2">FortiExtender 4.2.2</FullProductName>
                </Branch>
                <Branch Name="4.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.2.1">FortiExtender 4.2.1</FullProductName>
                </Branch>
                <Branch Name="4.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.2.0">FortiExtender 4.2.0</FullProductName>
                </Branch>
                <Branch Name="4.1.8" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.1.8">FortiExtender 4.1.8</FullProductName>
                </Branch>
                <Branch Name="4.1.7" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.1.7">FortiExtender 4.1.7</FullProductName>
                </Branch>
                <Branch Name="4.1.6" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.1.6">FortiExtender 4.1.6</FullProductName>
                </Branch>
                <Branch Name="4.1.5" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.1.5">FortiExtender 4.1.5</FullProductName>
                </Branch>
                <Branch Name="4.1.4" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.1.4">FortiExtender 4.1.4</FullProductName>
                </Branch>
                <Branch Name="4.1.3" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.1.3">FortiExtender 4.1.3</FullProductName>
                </Branch>
                <Branch Name="4.1.2" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.1.2">FortiExtender 4.1.2</FullProductName>
                </Branch>
                <Branch Name="4.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.1.1">FortiExtender 4.1.1</FullProductName>
                </Branch>
                <Branch Name="4.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.0.2">FortiExtender 4.0.2</FullProductName>
                </Branch>
                <Branch Name="4.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.0.1">FortiExtender 4.0.1</FullProductName>
                </Branch>
                <Branch Name="4.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-4.0.0">FortiExtender 4.0.0</FullProductName>
                </Branch>
                <Branch Name="3.3.2" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-3.3.2">FortiExtender 3.3.2</FullProductName>
                </Branch>
                <Branch Name="3.3.1" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-3.3.1">FortiExtender 3.3.1</FullProductName>
                </Branch>
                <Branch Name="3.3.0" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-3.3.0">FortiExtender 3.3.0</FullProductName>
                </Branch>
                <Branch Name="3.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-3.2.3">FortiExtender 3.2.3</FullProductName>
                </Branch>
                <Branch Name="3.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-3.2.2">FortiExtender 3.2.2</FullProductName>
                </Branch>
                <Branch Name="3.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-3.2.1">FortiExtender 3.2.1</FullProductName>
                </Branch>
                <Branch Name="3.1.2" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-3.1.2">FortiExtender 3.1.2</FullProductName>
                </Branch>
                <Branch Name="3.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-3.1.1">FortiExtender 3.1.1</FullProductName>
                </Branch>
                <Branch Name="3.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-3.1.0">FortiExtender 3.1.0</FullProductName>
                </Branch>
                <Branch Name="3.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-3.0.2">FortiExtender 3.0.2</FullProductName>
                </Branch>
                <Branch Name="3.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-3.0.1">FortiExtender 3.0.1</FullProductName>
                </Branch>
                <Branch Name="3.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiExtender-3.0.0">FortiExtender 3.0.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Multiple command injection vulnerabilities in webserver</Title>
        <cvrf:CVE>CVE-2022-27489</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiExtender-7.0.3</ProductID>
                <ProductID>FortiExtender-7.0.2</ProductID>
                <ProductID>FortiExtender-7.0.1</ProductID>
                <ProductID>FortiExtender-7.0.0</ProductID>
                <ProductID>FortiExtender-5.3.2</ProductID>
                <ProductID>FortiExtender-4.2.4</ProductID>
                <ProductID>FortiExtender-4.2.3</ProductID>
                <ProductID>FortiExtender-4.2.2</ProductID>
                <ProductID>FortiExtender-4.2.1</ProductID>
                <ProductID>FortiExtender-4.2.0</ProductID>
                <ProductID>FortiExtender-4.1.8</ProductID>
                <ProductID>FortiExtender-4.1.7</ProductID>
                <ProductID>FortiExtender-4.1.6</ProductID>
                <ProductID>FortiExtender-4.1.5</ProductID>
                <ProductID>FortiExtender-4.1.4</ProductID>
                <ProductID>FortiExtender-4.1.3</ProductID>
                <ProductID>FortiExtender-4.1.2</ProductID>
                <ProductID>FortiExtender-4.1.1</ProductID>
                <ProductID>FortiExtender-4.0.2</ProductID>
                <ProductID>FortiExtender-4.0.1</ProductID>
                <ProductID>FortiExtender-4.0.0</ProductID>
                <ProductID>FortiExtender-3.3.2</ProductID>
                <ProductID>FortiExtender-3.3.1</ProductID>
                <ProductID>FortiExtender-3.3.0</ProductID>
                <ProductID>FortiExtender-3.2.3</ProductID>
                <ProductID>FortiExtender-3.2.2</ProductID>
                <ProductID>FortiExtender-3.2.1</ProductID>
                <ProductID>FortiExtender-3.1.2</ProductID>
                <ProductID>FortiExtender-3.1.1</ProductID>
                <ProductID>FortiExtender-3.1.0</ProductID>
                <ProductID>FortiExtender-3.0.2</ProductID>
                <ProductID>FortiExtender-3.0.1</ProductID>
                <ProductID>FortiExtender-3.0.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>7.0</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-22-048</URL>
                <Description>Multiple command injection vulnerabilities in webserver</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>