Executive Risk Summary
"A vulnerability in Fortinet FortiExtender versions 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, and all versions of 7.2 and 7.0 may allow an authenticated attacker to execute unauthorized code or commands via a specific HTTP request, potentially leading to code injection and system compromise. This vulnerability poses a significant risk to the security and integrity of affected systems, as it could be exploited to gain unauthorized access or disrupt system operations."
Operational Audit Arsenal
Manual Verification Required
This is a non-Windows asset (Fortinet). Use the target asset details above to verify your version against vendor advisories.
Patch Impact Forecast
Moderate to High
Internal Work Notes
Technical Intelligence & Operational Utilities • Delivered Weekly
Intelligence Sources
Scope of Impact
Original NVD Description
"A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExtender 7.4.0 through 7.4.7, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via a specific HTTP request."