Executive Risk Summary
"A remote and authenticated attacker with low privilege can execute unauthorized code via specifically crafted HTTP parameters due to an OS Command Injection vulnerability in Fortinet FortiADC version 7.2.0 and before 7.1.1. This vulnerability allows attackers to potentially disrupt or take control of the affected system, leading to critical data integrity risks."
Operational Audit Arsenal
Manual Verification Required
This is a non-Windows asset (Fortinet). Use the target asset details above to verify your version against vendor advisories.
Patch Impact Forecast
Moderate to High
Internal Work Notes
Technical Intelligence & Operational Utilities • Delivered Weekly
Intelligence Sources
Scope of Impact
Original NVD Description
"An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a remote and authenticated attacker with low privilege to execute unauthorized code via specifically crafted HTTP parameters."