A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U below 6.0.0 under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted ifconfig commands.
2020-03-15T23:15:11.327
2024-11-21T04:29:17.990
Modified
CVSSv3.1: 6.7 (MEDIUM)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiap | ≤ 6.0.5 | Yes |
Application | fortinet | fortiap-s | ≤ 6.0.5 | Yes |
Application | fortinet | fortiap-s | 6.2.0 | Yes |
Application | fortinet | fortiap-s | 6.2.1 | Yes |
Application | fortinet | fortiap-u | ≤ 6.0.0 | Yes |
Application | fortinet | fortiap-w2 | ≤ 6.0.5 | Yes |
Application | fortinet | fortiap-w2 | 6.2.0 | Yes |
Application | fortinet | fortiap-w2 | 6.2.1 | Yes |