CVE-2019-15710
published 2019-10-31CVE-2019-15710: An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run…
PriorityP348high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.91%
77.3th percentile
An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted "execute date" commands.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortiguard | fortiextender_firmware | <= 4.1.1 | — |
| fortinet | fortiextender | — | — |
| fortinet | fortiextender | — | — |
| fortinet | fortiextender | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qwvq-972q-36q5: An OS command injection vulnerability in FortiExtender 4
ghsa_unreviewed·2022-05-24
CVE-2019-15710 [HIGH] CWE-78 GHSA-qwvq-972q-36q5: An OS command injection vulnerability in FortiExtender 4
An OS command injection vulnerability in FortiExtender 4.1.1 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted "execute date" commands.
Fortinet
An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow...
vendor_fortinet·2019-10-31·CVSS 7.2
CVE-2019-15710 [HIGH] CWE-78 An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow...
FG-IR-19-273: An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow...
An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted "execute date" commands.
CVEs: CVE-2019-15710
CWEs: CWE-78
CVSS: 7.2 (high)
Affected products: FortiExtender
No detection rules found.
No writeups or analysis indexed.
2019-10-31
Published