Description
An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.An OS command injection (CWE-78) vulnerability in FortiWAN Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.
Published: 2024-12-19
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Please upgrade to FortiWAN version 4.5.8 or above.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-12936 An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.An OS command injection (CWE-78) vulnerability in FortiWAN Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.
History

Tue, 21 Jan 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Fortinet
Fortinet fortiwan
CPEs cpe:2.3:a:fortinet:fortiwan:*:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortiwan

Fri, 20 Dec 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 19 Dec 2024 11:15:00 +0000

Type Values Removed Values Added
Description An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.An OS command injection (CWE-78) vulnerability in FortiWAN Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:C'}


Subscriptions

Fortinet Fortiwan
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2024-12-20T17:22:16.068Z

Reserved: 2021-01-25T14:47:15.100Z

Link: CVE-2021-26115

cve-icon Vulnrichment

Updated: 2024-12-20T17:22:09.695Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-19T11:15:07.103

Modified: 2025-01-21T20:30:46.950

Link: CVE-2021-26115

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses