Fortinet FortiOS
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*
- >= 7.6.0, <= 7.6.2
- >= 7.4.0, <= 7.4.7
- >= 7.2.0, <= 7.2.10
- >= 7.0.0, <= 7.0.16
- ~6.4
A vulnerability allowing execution of Lua scripts via crafted CLI commands has been identified in Fortinet FortiOS and FortiProxy. This issue affects multiple versions across FortiOS 7.6, 7.4, 7.2, 7.0, FortiOS 6.4, and various FortiProxy 7.0 versions. The vulnerability arises from an internal asset being exposed to an unsafe debug access level, which may allow an authenticated admin to exploit the CLI.
Exploitation of this vulnerability could lead to unauthorized execution of code or commands on the affected system.
Users are advised to upgrade Fortinet FortiOS or FortiProxy to the latest versions. Specific upgrade recommendations include FortiOS 7.6.3, 7.4.8, 7.2.11, FortiProxy 7.6.4, 7.4.11, and 7.2.15. Follow the recommended upgrade path using the Fortinet upgrade tool.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.