OS command injection in CLI commands
Summary
An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiIsolator may allow a privileged attacker to execute arbitrary OS commands in the underlying shell via specially crafted input parameters.
Affected Products
FortiIsolator version 1.0.0
FortiIsolator version 1.1.0
FortiIsolator version 1.2.0 through 1.2.2
FortiIsolator version 2.0.0 through 2.0.1
FortiIsolator version 2.1.0 through 2.1.2
FortiIsolator version 2.2.0
FortiIsolator version 2.3.0 through 2.3.4
Solutions
Upgrade to FortiIsolator version 2.4.0 or above.
Acknowledgement
Internally discovered and reported by Mattia Fecit of Fortinet Product Security team.Timeline
2023-10-10: Initial publication