Fortinet FortiManager
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*, +1 more
- >= 7.6.0, <= 7.6.1
- >= 7.4.0, <= 7.4.5
- >= 7.4.0, <= 7.4.4
- >= 7.2.1, <= 7.2.8
- >= 7.2.2, <= 7.2.7
An OS command injection vulnerability has been identified in Fortinet FortiManager. This issue affects versions 7.6.0 through 7.6.1, 7.4.5 through 7.4.0, and 7.2.1 through 7.2.8, as well as FortiManager Cloud versions 7.6.0 through 7.6.1, 7.4.0 through 7.4.4, and 7.2.2 through 7.2.7. The vulnerability arises from improper neutralization of special elements in OS commands, which may allow an authenticated remote attacker to execute unauthorized code by sending crafted FGFM requests.
Exploitation of this vulnerability could lead to unauthorized code execution on the affected FortiManager instance.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.