cbcvebase.
CVE-2022-33872
published 2022-10-18

CVE-2022-33872: An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of…

PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.84%
85.1th percentile
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.

Affected

5 ranges
VendorProductVersion rangeFixed in
fortinetfortinet_fortitester
fortinetfortitester
fortinetfortitester>= 2.3.0 < 3.9.23.9.2
fortinetfortitester>= 4.0.0 < 4.2.14.2.1
fortinetfortitester>= 7.0.0 < 7.1.17.1.1

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for OS command injection attempts via the Telnet login component of FortiTester, which may allow unauthenticated remote code execution in the underlying shell.
  • Monitor for OS command injection attempts via the SSH login component of FortiTester, which may allow unauthenticated remote code execution in the underlying shell.
  • Monitor for OS command injection attempts via the Console login component of FortiTester, which may allow unauthenticated local/physical code execution in the underlying shell.
  • ·CVE-2022-33872 specifically covers the Telnet login attack surface; CVE-2022-33873 covers Console login; CVE-2022-33874 covers SSH login — all three share the same CWE-78 OS Command Injection root cause and affect the same FortiTester version ranges (2.3.0–3.9.1, 4.0.0–4.2.0, 7.0.0–7.1.0). Detections should be scoped per login protocol accordingly.
  • ·All three vulnerabilities are exploitable by unauthenticated attackers (Telnet and SSH remotely; Console physically), with a CVSS score of 9.8 (Critical), meaning no credentials are required to trigger command injection at the login prompt.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.