Impact
The Fortinet FortiOS and FortiProxy products contain an internal asset exposure that allows an authenticated administrator to invoke arbitrary Lua scripts through specially crafted command‑line instructions. This weakness, classified as CWE‑1244, provides an attacker with the ability to execute code with full administrative privileges on the system, potentially enabling further compromise of the network infrastructure.
Affected Systems
Affected systems are Fortinet FortiOS versions 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, and all 6.4 releases; and FortiProxy versions 7.6.0 through 7.6.3, 7.4.0 through 7.4.10, 7.2.0 through 7.2.14, and all 7.0 releases. The minimum non‑vulnerable firmware for each product line is FortiOS 7.6.3, 7.4.8, 7.2.11, or 7.0.17, and FortiProxy 7.6.4, 7.4.11, or 7.2.15.
Risk and Exploitability
The CVSS score of 6 indicates a moderate level of risk, and an EPSS score is not presently available, suggesting uncertainty about current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog, which implies it has not been confirmed as a known exploited weakness in the wild. Attacks would require authenticated administrative access to the CLI, and thus the attack vector is primarily internal and privilege‑based. While the exploitation path is straightforward for an attacker who has gained such access, the lack of public exploitation evidence may moderate overall threat perception.
OpenCVE Enrichment