OS Command Injection in FortiADC Manager and FortiADC - CVE-2023-26210

 

OS Command Injection in FortiADC Manager and FortiADC - CVE-2023-26210

Published: June 13, 2023


Vulnerability identifier: #VU77196
CSH Severity: Low
CVSS v4: 9.2 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N]
CVE-ID: CVE-2023-26210
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper input validation in certain CLI commands. A local user can pass specially crafted arguments to the CLI commands and execute arbitrary OS commands on the target system as root.


Affected software

FortiADC Manager
FortiADC

How to mitigate CVE-2023-26210

Install updates from vendor's website.

FortiADC Manager - addressed in versions 7.0.1, 7.1.1, 7.2.0
FortiADC - addressed in versions 7.1.3, 7.2.1

External References

Related Security Bulletins