OS Command Injection in FortiAnalyzer and FortiManager - CVE-2022-27483
Published: July 5, 2022
Vulnerability identifier: #VU64938
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-27483
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation. A remote user can pass specially crafted data to the application and execute arbitrary OS commands as root user via the "diagnose system" CLI commands.
Affected software
FortiAnalyzer
FortiManager
FortiManager
How to mitigate CVE-2022-27483
Install updates from vendor's website.
FortiAnalyzer - addressed in versions 6.4.8, 7.0.4
FortiManager - addressed in versions 6.4.8, 7.0.4
FortiManager - addressed in versions 6.4.8, 7.0.4