OS command injection on gen-ca-cert command

Summary

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiIsolator CLI may allow a privileged attacker to execute unauthorized code or commands via crafted CLI requests.

Version Affected Solution
FortiIsolator 3.0 Not affected Not Applicable
FortiIsolator 2.4 2.4.3 through 2.4.6 Upgrade to 2.4.7 or above
FortiIsolator 2.3 Not affected Not Applicable
FortiIsolator 2.2 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Adham El karn of Fortinet Product Security team.

Timeline

2025-04-08: Initial publication