An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to commands of the certificate import feature.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2022-10-10T00:00:00

Updated: 2024-08-03T09:44:22.172Z

Reserved: 2022-07-13T00:00:00

Link: CVE-2022-35844

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-10-18T14:15:09.590

Modified: 2022-10-20T18:50:42.873

Link: CVE-2022-35844

cve-icon Redhat

No data.