Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an attacker who has already obtained a non-login low privileged shell access (via another hypothetical vulnerability) to perform a local privilege escalation via crafted commands.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Fortinet FortiSOAR 操作系统命令注入漏洞
Vulnerability Description
Fortinet FortiSOAR是美国飞塔(Fortinet)公司的一种安全编排、自动化和响应 (SOAR) 解决方案。 Fortinet FortiSOAR存在操作系统命令注入漏洞,该漏洞源于特殊元素中和不当,可能导致本地权限提升。以下版本受到影响:7.6.0版本至7.6.1版本、7.5.0版本至7.5.1版本、7.4所有版本和7.3所有版本。
CVSS Information
N/A
Vulnerability Type
N/A