cbcvebase.
CVE-2022-33874
published 2022-10-18

CVE-2022-33874: An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.

Affected

5 ranges
VendorProductVersion rangeFixed in
fortinetfortinet_fortitester
fortinetfortitester
fortinetfortitester>= 2.3.0 < 3.9.23.9.2
fortinetfortitester>= 4.0.0 < 4.2.14.2.1
fortinetfortitester>= 7.0.0 < 7.1.17.1.1