Wednesday, October 27, 2021

Fortinet FortiWeb OS Command Injection – post authentication like the Pulse VPN issues – so risk is from password spraying etc.

An OS command injection vulnerability in FortiWeb’s management interface (version 6.3.11 and prior) can allow a remote, authenticated attacker to execute arbitrary commands on the system, via the SAML server configuration page. This is an instance of CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) and has a CVSSv3 base score of 8.7. This vulnerability appears to be related to CVE-2021-22123, which was addressed in FG-IR-20-120.

Product Descript…

Read More

Latest news
Related news