Overview
- Description
- An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted "execute date" commands.
- Source
- psirt@fortinet.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.2
- Impact score
- 5.9
- Exploitability score
- 1.2
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 9
- Impact score
- 10
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-78
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:fortiguard:fortiextender_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "93E3F6EC-6DDB-48F3-AC58-801B6AFC6E0E", "versionEndIncluding": "4.1.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:fortiguard:fortiextender:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E7AA5432-CDD1-4038-8B21-0ACD29EC73A6" } ], "operator": "OR" } ], "operator": "AND" } ]