Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, 7.1.0; FortiDDoS 4.x all versions, 5.0 all versions, 5.1 all versions, 5.2 all versions, 5.3 all versions, 5.4 all versions, 5.5 all versions, 5.6 all versions and FortiDDoS-F 6.4.0, 6.3.0 through 6.3.3, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Fortinet FortiADC、FortiDDoS和FortiDDoS-F 操作系统命令注入漏洞
Vulnerability Description
Fortinet FortiADC和Fortinet FortiDDoS都是美国飞塔(Fortinet)公司的产品。Fortinet FortiADC是一款应用交付控制器。Fortinet FortiDDoS是一个唯一可以检查的 DDoS 缓解平台。 FortiADC、FortiDDoS和FortiDDoS-F存在安全漏洞,该漏洞源于使用的特殊元素的不当中和,存在操作系统命令漏洞,攻击者利用该漏洞可以通过特制的现有命令参数执行未经授权的命令。
CVSS Information
N/A
Vulnerability Type
N/A