Fortinet FortiManager and FortiAnalyzer OS Command Injection Vulnerability

Vulnerability

A vulnerability allowing OS command injection has been identified in Fortinet FortiManager and FortiAnalyzer. This issue affects multiple versions across several release branches: 7.4.0 to 7.4.2, 7.2.0 to 7.2.5, 7.0.0 to 7.0.12, 6.4.0 to 6.4.14, 6.2.0 to 6.2.12, 6.0.0 to 6.0.12, 5.6.0 to 5.6.11, 5.4.0 to 5.4.7, 5.2.0 to 5.2.10, and 5.0.0 to 5.0.12. The vulnerability arises from multiple instances of improper neutralization of special elements, which could allow an attacker to execute unauthorized code or commands by sending crafted CLI requests.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code or commands on the affected system.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
7.5
exploitability
4.8
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.