An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiAP 6.0.0 through 6.4.7, 7.0.0 through 7.0.3, 7.2.0, FortiAP-S 6.0.0 through 6.4.7, FortiAP-W2 6.0.0 through 6.4.7, 7.0.0 through 7.0.3, 7.2.0 and FortiAP-U 5.4.0 through 6.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
2022-09-06T18:15:13.053
2024-11-21T06:58:25.527
Modified
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiap | ≤ 6.0.6 | Yes |
Application | fortinet | fortiap | < 6.4.8 | Yes |
Application | fortinet | fortiap | < 7.0.4 | Yes |
Application | fortinet | fortiap | 7.2.0 | Yes |
Application | fortinet | fortiap-s | ≤ 6.0.6 | Yes |
Application | fortinet | fortiap-s | ≤ 6.2.6 | Yes |
Application | fortinet | fortiap-s | < 6.4.8 | Yes |
Application | fortinet | fortiap-u | ≤ 5.4.6 | Yes |
Application | fortinet | fortiap-u | ≤ 6.0.4 | Yes |
Application | fortinet | fortiap-u | < 6.2.4 | Yes |
Application | fortinet | fortiap-w2 | ≤ 6.0.6 | Yes |
Application | fortinet | fortiap-w2 | ≤ 6.2.6 | Yes |
Application | fortinet | fortiap-w2 | < 6.4.8 | Yes |
Application | fortinet | fortiap-w2 | < 7.0.4 | Yes |
Application | fortinet | fortiap-w2 | 7.2.0 | Yes |