Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-44171


A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.3 allows attacker to execute privileged commands on a linked FortiSwitch via diagnostic CLI commands.


Published

2022-10-10T14:15:09.650

Last Modified

2024-11-21T06:30:29.923

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.0 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System fortinet fortios ≤ 6.0.14 Yes
Operating System fortinet fortios ≤ 6.2.10 Yes
Operating System fortinet fortios ≤ 6.4.8 Yes
Operating System fortinet fortios ≤ 7.0.3 Yes

References