CVE-2022-33873
published 2022-10-18CVE-2022-33873: An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of…
PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.57%
83.5th percentile
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to execute arbitrary command in the underlying shell.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet_fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | >= 2.3.0 < 3.9.2 | 3.9.2 |
| fortinet | fortitester | >= 4.0.0 < 4.2.1 | 4.2.1 |
| fortinet | fortitester | >= 7.0.0 < 7.1.1 | 7.1.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for OS command injection attempts via the Telnet login component of FortiTester (unauthenticated remote vector) ↗
- →Monitor for OS command injection attempts via the SSH login component of FortiTester (unauthenticated remote vector) ↗
- →Monitor for OS command injection attempts via the Console login component of FortiTester (unauthenticated local/physical vector) ↗
- ·CVE-2022-33873 specifically covers the Console login vector; CVE-2022-33872 and CVE-2022-33874 are sibling CVEs covering SSH and Telnet login vectors respectively — all three share the same affected version ranges and CWE-78 root cause under FG-IR-22-237 ↗
- ·All three attack vectors (Telnet, SSH, Console) are pre-authentication, meaning no credentials are required to trigger command injection — treat any anomalous shell activity originating from these login daemons as high-priority ↗
- ·Affected FortiTester versions span three distinct ranges: 2.3.0–3.9.1, 4.0.0–4.2.0, and 7.0.0–7.1.0; ensure version fingerprinting covers all three ranges during asset inventory ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pgv3-vv3g-qp7g: An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of
ghsa_unreviewed·2022-10-18
CVE-2022-33873 [CRITICAL] CWE-78 GHSA-pgv3-vv3g-qp7g: An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to execute arbitrary command in the underlying shell.
Fortinet
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] i...
vendor_fortinet·2022-10-18·CVSS 9.8
CVE-2022-33872 [CRITICAL] CWE-78 An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] i...
FG-IR-22-237: An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] i...
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to execute arbitrary command in the underlying shell.
An improper neutraliz
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-18
Published