Code Injection in FortiOS - CVE-2021-36169
Published: September 7, 2021
FortiOS
Fortinet, Inc
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper input validation within the debug functionality in FortiGate. A local privileged user can execute unauthorized code or commands via specific
chains of `print str` and `cmd mem` cli commands to, respectively, read and write hexadecimal values to any memory address.