Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 through 4.5.9 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Fortinet FortiWAN 操作系统命令注入漏洞
Vulnerability Description
Fortinet FortiWAN是美国飞塔(Fortinet)公司的一个网络设备。用于在不同网络之间执行负载平衡和容错。 Fortinet FortiWAN 4.0.0版本至4.5.9版本存在安全漏洞,该漏洞源于对特殊元素中和不当。攻击者利用该漏洞通过特制的命令参数执行未经授权的命令。
CVSS Information
N/A
Vulnerability Type
N/A