#VU54847 OS Command Injection in Fortinet, Inc products - CVE-2021-26106 

 

#VU54847 OS Command Injection in Fortinet, Inc products - CVE-2021-26106

Published: July 14, 2021


Vulnerability identifier: #VU54847
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-26106
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
FortiAP
FortiAP-S
FortiAP-W2
Software vendor:
Fortinet, Inc

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper input validation within the kdbg CLI command. A local user can pass specially crafted input to the affected kdbg CLI command and execute arbitrary OS commands on the system with elevated privileges.


Remediation

Install updates from vendor's website.

External links