OS command injection

Summary

An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData may allow a local attacker with low privileges to execute unauthorized code via specifically crafted arguments to a CLI command

Version Affected Solution
FortiAnalyzer 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiAnalyzer 7.2 7.2.0 through 7.2.3 Upgrade to 7.2.4 or above
FortiAnalyzer 7.0 7.0.0 through 7.0.8 Upgrade to 7.0.9 or above
FortiAnalyzer 6.4 6.4.0 through 6.4.12 Upgrade to 6.4.13 or above
FortiAnalyzer 6.2 6.2.0 through 6.2.11 Upgrade to 6.2.12 or above
FortiAnalyzer-BigData 7.4 Not affected Not Applicable
FortiAnalyzer-BigData 7.2 7.2.0 through 7.2.5 Upgrade to 7.2.6 or above
FortiAnalyzer-BigData 7.0 7.0 all versions Migrate to a fixed release
FortiAnalyzer-BigData 6.4 6.4 all versions Migrate to a fixed release
FortiAnalyzer-BigData 6.2 6.2 all versions Migrate to a fixed release
FortiManager 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiManager 7.2 7.2.0 through 7.2.3 Upgrade to 7.2.4 or above
FortiManager 7.0 7.0.0 through 7.0.8 Upgrade to 7.0.9 or above
FortiManager 6.4 6.4.0 through 6.4.12 Upgrade to 6.4.13 or above
FortiManager 6.2 6.2.0 through 6.2.11 Upgrade to 6.2.12 or above
FortiManager Cloud 7.4 Not affected Not Applicable
FortiManager Cloud 7.2 7.2.1 through 7.2.3 Upgrade to 7.2.4 or above
FortiManager Cloud 7.0 7.0.1 through 7.0.8 Upgrade to 7.0.9 or above
FortiManager Cloud 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank security researchers Loc Restoux and Orange CERT-CC at Orange group for discovering and reporting this vulnerability under responsible disclosure.

Timeline

2023-10-10: Initial publication
2025-01-27: Adding FAZ and FAZBD
2025-05-13: Adding FortiManager Cloud
2025-06-10: Add FortiAnalyzer-Cloud product