<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Command injection vulnerabilities in cli commands</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-23-076</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2023-06-12T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2023-06-12T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2023-06-12T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            Multiple improper neutralization of special elements used in an os command (&#39;OS Command Injection&#39;) vulnerabilties [CWE-78] in FortiADC &amp; FortiADC Manager may allow a local authenticated attacker to execute arbitrary shell code as root user via crafted CLI requests.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Execute unauthorized code or commands
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiADC version 7.2.0FortiADC version 7.1.0 through 7.1.2FortiADC 7.0 all versionsFortiADC 6.2 all versionsFortiADC 6.1 all versionsFortiADC 6.0 all versionsFortiADC 5.4 all versionsFortiADC 5.3 all versionsFortiADC 5.2 all versionsAt leastFortiADCManager 7.2 all versions are not affectedFortiADCManager version 7.1.0FortiADCManager version 7.0.0FortiADCManager 6.2 all versionsFortiADCManager 6.1 all versionsFortiADCManager 6.0 all versionsFortiADCManager 5.4 all versionsFortiADCManager 5.3 all versionsFortiADCManager 5.2 all versions
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiADC version 7.2.1 or abovePlease upgrade to FortiADC version 7.1.3 or abovePlease upgrade to FortiADCManager version 7.2.0 or abovePlease upgrade to FortiADCManager version 7.1.1 or abovePlease upgrade to FortiADCManager version 7.0.1 or above
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Internally discovered and reported by Théo Leleu and Giulia Clerici of Fortinet Product Security team.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiADC" Type="Product Name">
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-7.2.0">FortiADC 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.1.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-7.1.2">FortiADC 7.1.2</FullProductName>
                </Branch>
                <Branch Name="7.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-7.1.1">FortiADC 7.1.1</FullProductName>
                </Branch>
                <Branch Name="7.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-7.1.0">FortiADC 7.1.0</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiADC-7.0.6">FortiADC 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiADC-7.0.5">FortiADC 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-7.0.4">FortiADC 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-7.0.3">FortiADC 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-7.0.2">FortiADC 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-7.0.1">FortiADC 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-7.0.0">FortiADC 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.6">FortiADC 6.2.6</FullProductName>
                </Branch>
                <Branch Name="6.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.5">FortiADC 6.2.5</FullProductName>
                </Branch>
                <Branch Name="6.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.4">FortiADC 6.2.4</FullProductName>
                </Branch>
                <Branch Name="6.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.3">FortiADC 6.2.3</FullProductName>
                </Branch>
                <Branch Name="6.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.2">FortiADC 6.2.2</FullProductName>
                </Branch>
                <Branch Name="6.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.1">FortiADC 6.2.1</FullProductName>
                </Branch>
                <Branch Name="6.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.0">FortiADC 6.2.0</FullProductName>
                </Branch>
                <Branch Name="6.1.6" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.1.6">FortiADC 6.1.6</FullProductName>
                </Branch>
                <Branch Name="6.1.5" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.1.5">FortiADC 6.1.5</FullProductName>
                </Branch>
                <Branch Name="6.1.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.1.4">FortiADC 6.1.4</FullProductName>
                </Branch>
                <Branch Name="6.1.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.1.3">FortiADC 6.1.3</FullProductName>
                </Branch>
                <Branch Name="6.1.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.1.2">FortiADC 6.1.2</FullProductName>
                </Branch>
                <Branch Name="6.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.1.1">FortiADC 6.1.1</FullProductName>
                </Branch>
                <Branch Name="6.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.1.0">FortiADC 6.1.0</FullProductName>
                </Branch>
                <Branch Name="6.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.0.4">FortiADC 6.0.4</FullProductName>
                </Branch>
                <Branch Name="6.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.0.3">FortiADC 6.0.3</FullProductName>
                </Branch>
                <Branch Name="6.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.0.2">FortiADC 6.0.2</FullProductName>
                </Branch>
                <Branch Name="6.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.0.1">FortiADC 6.0.1</FullProductName>
                </Branch>
                <Branch Name="6.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.0.0">FortiADC 6.0.0</FullProductName>
                </Branch>
                <Branch Name="5.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.4.5">FortiADC 5.4.5</FullProductName>
                </Branch>
                <Branch Name="5.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.4.4">FortiADC 5.4.4</FullProductName>
                </Branch>
                <Branch Name="5.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.4.3">FortiADC 5.4.3</FullProductName>
                </Branch>
                <Branch Name="5.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.4.2">FortiADC 5.4.2</FullProductName>
                </Branch>
                <Branch Name="5.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.4.1">FortiADC 5.4.1</FullProductName>
                </Branch>
                <Branch Name="5.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.4.0">FortiADC 5.4.0</FullProductName>
                </Branch>
                <Branch Name="5.3.7" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.7">FortiADC 5.3.7</FullProductName>
                </Branch>
                <Branch Name="5.3.6" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.6">FortiADC 5.3.6</FullProductName>
                </Branch>
                <Branch Name="5.3.5" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.5">FortiADC 5.3.5</FullProductName>
                </Branch>
                <Branch Name="5.3.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.4">FortiADC 5.3.4</FullProductName>
                </Branch>
                <Branch Name="5.3.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.3">FortiADC 5.3.3</FullProductName>
                </Branch>
                <Branch Name="5.3.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.2">FortiADC 5.3.2</FullProductName>
                </Branch>
                <Branch Name="5.3.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.1">FortiADC 5.3.1</FullProductName>
                </Branch>
                <Branch Name="5.3.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.3.0">FortiADC 5.3.0</FullProductName>
                </Branch>
                <Branch Name="5.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.8">FortiADC 5.2.8</FullProductName>
                </Branch>
                <Branch Name="5.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.7">FortiADC 5.2.7</FullProductName>
                </Branch>
                <Branch Name="5.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.6">FortiADC 5.2.6</FullProductName>
                </Branch>
                <Branch Name="5.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.5">FortiADC 5.2.5</FullProductName>
                </Branch>
                <Branch Name="5.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.4">FortiADC 5.2.4</FullProductName>
                </Branch>
                <Branch Name="5.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.3">FortiADC 5.2.3</FullProductName>
                </Branch>
                <Branch Name="5.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.2">FortiADC 5.2.2</FullProductName>
                </Branch>
                <Branch Name="5.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.1">FortiADC 5.2.1</FullProductName>
                </Branch>
                <Branch Name="5.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-5.2.0">FortiADC 5.2.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiADCManager" Type="Product Name">
                <Branch Name="7.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiADCManager-7.1.0">FortiADCManager 7.1.0</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiADCManager-7.0.0">FortiADCManager 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiADCManager-6.2.1">FortiADCManager 6.2.1</FullProductName>
                </Branch>
                <Branch Name="6.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiADCManager-6.2.0">FortiADCManager 6.2.0</FullProductName>
                </Branch>
                <Branch Name="6.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiADCManager-6.1.0">FortiADCManager 6.1.0</FullProductName>
                </Branch>
                <Branch Name="6.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiADCManager-6.0.0">FortiADCManager 6.0.0</FullProductName>
                </Branch>
                <Branch Name="5.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiADCManager-5.4.0">FortiADCManager 5.4.0</FullProductName>
                </Branch>
                <Branch Name="5.3.0" Type="Product Version">
                    <FullProductName ProductID="FortiADCManager-5.3.0">FortiADCManager 5.3.0</FullProductName>
                </Branch>
                <Branch Name="5.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiADCManager-5.2.1">FortiADCManager 5.2.1</FullProductName>
                </Branch>
                <Branch Name="5.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiADCManager-5.2.0">FortiADCManager 5.2.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Command injection vulnerabilities in cli commands</Title>
        <cvrf:CVE>CVE-2023-26210</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiADC-7.2.0</ProductID>
                <ProductID>FortiADC-7.1.2</ProductID>
                <ProductID>FortiADC-7.1.1</ProductID>
                <ProductID>FortiADC-7.1.0</ProductID>
                <ProductID>FortiADC-7.0.6</ProductID>
                <ProductID>FortiADC-7.0.5</ProductID>
                <ProductID>FortiADC-7.0.4</ProductID>
                <ProductID>FortiADC-7.0.3</ProductID>
                <ProductID>FortiADC-7.0.2</ProductID>
                <ProductID>FortiADC-7.0.1</ProductID>
                <ProductID>FortiADC-7.0.0</ProductID>
                <ProductID>FortiADC-6.2.6</ProductID>
                <ProductID>FortiADC-6.2.5</ProductID>
                <ProductID>FortiADC-6.2.4</ProductID>
                <ProductID>FortiADC-6.2.3</ProductID>
                <ProductID>FortiADC-6.2.2</ProductID>
                <ProductID>FortiADC-6.2.1</ProductID>
                <ProductID>FortiADC-6.2.0</ProductID>
                <ProductID>FortiADC-6.1.6</ProductID>
                <ProductID>FortiADC-6.1.5</ProductID>
                <ProductID>FortiADC-6.1.4</ProductID>
                <ProductID>FortiADC-6.1.3</ProductID>
                <ProductID>FortiADC-6.1.2</ProductID>
                <ProductID>FortiADC-6.1.1</ProductID>
                <ProductID>FortiADC-6.1.0</ProductID>
                <ProductID>FortiADC-6.0.4</ProductID>
                <ProductID>FortiADC-6.0.3</ProductID>
                <ProductID>FortiADC-6.0.2</ProductID>
                <ProductID>FortiADC-6.0.1</ProductID>
                <ProductID>FortiADC-6.0.0</ProductID>
                <ProductID>FortiADC-5.4.5</ProductID>
                <ProductID>FortiADC-5.4.4</ProductID>
                <ProductID>FortiADC-5.4.3</ProductID>
                <ProductID>FortiADC-5.4.2</ProductID>
                <ProductID>FortiADC-5.4.1</ProductID>
                <ProductID>FortiADC-5.4.0</ProductID>
                <ProductID>FortiADC-5.3.7</ProductID>
                <ProductID>FortiADC-5.3.6</ProductID>
                <ProductID>FortiADC-5.3.5</ProductID>
                <ProductID>FortiADC-5.3.4</ProductID>
                <ProductID>FortiADC-5.3.3</ProductID>
                <ProductID>FortiADC-5.3.2</ProductID>
                <ProductID>FortiADC-5.3.1</ProductID>
                <ProductID>FortiADC-5.3.0</ProductID>
                <ProductID>FortiADC-5.2.8</ProductID>
                <ProductID>FortiADC-5.2.7</ProductID>
                <ProductID>FortiADC-5.2.6</ProductID>
                <ProductID>FortiADC-5.2.5</ProductID>
                <ProductID>FortiADC-5.2.4</ProductID>
                <ProductID>FortiADC-5.2.3</ProductID>
                <ProductID>FortiADC-5.2.2</ProductID>
                <ProductID>FortiADC-5.2.1</ProductID>
                <ProductID>FortiADC-5.2.0</ProductID>
                <ProductID>FortiADCManager-7.1.0</ProductID>
                <ProductID>FortiADCManager-7.0.0</ProductID>
                <ProductID>FortiADCManager-6.2.1</ProductID>
                <ProductID>FortiADCManager-6.2.0</ProductID>
                <ProductID>FortiADCManager-6.1.0</ProductID>
                <ProductID>FortiADCManager-6.0.0</ProductID>
                <ProductID>FortiADCManager-5.4.0</ProductID>
                <ProductID>FortiADCManager-5.3.0</ProductID>
                <ProductID>FortiADCManager-5.2.1</ProductID>
                <ProductID>FortiADCManager-5.2.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>7.8</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:X/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-23-076</URL>
                <Description>Command injection vulnerabilities in cli commands</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>