Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-35844


An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to commands of the certificate import feature.


Published

2022-10-18T14:15:09.590

Last Modified

2024-11-21T07:11:48.393

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortitester < 3.9.2 Yes
Application fortinet fortitester < 4.2.1 Yes
Application fortinet fortitester < 7.1.1 Yes

References