CVE-2022-35845
published 2023-01-03CVE-2022-35845: Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.0 all…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.11%
62.4th percentile
Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.0 all versions, 4.0.0 through 4.2.0, 2.3.0 through 3.9.1 may allow an authenticated attacker to execute arbitrary commands in the underlying shell.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | — | — |
| fortinet | fortitester | 2.3.0 – 3.9.1 | — |
| fortinet | fortitester | 2.4.0 – 2.4.1 | — |
| fortinet | fortitester | 3.3.0 – 3.3.1 | — |
| fortinet | fortitester | 3.5.0 – 3.5.1 | — |
| fortinet | fortitester | 3.7.0 – 3.7.1 | — |
| fortinet | fortitester | 3.9.0 – 3.9.1 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Authenticated OS command injection in FortiTester — monitor for unexpected shell command execution originating from the FortiTester process/service, particularly from authenticated sessions ↗
- →Affected versions of FortiTester to target for detection/patching: 7.1.0, all 7.0.x, 4.0.0–4.2.0, and 2.3.0–3.9.1; traffic or logs from these versions should be treated as high-risk ↗
- ·Exploitation requires prior authentication; prioritize monitoring and hardening of authenticated user sessions and access controls on FortiTester management interfaces ↗
- ·Multiple injection points are affected (plural 'vulnerabilities'), meaning the attack surface is not limited to a single endpoint or parameter within FortiTester ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h5mf-c7gh-2f5g: Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7
ghsa_unreviewed·2023-01-03
CVE-2022-35845 [HIGH] CWE-78 GHSA-h5mf-c7gh-2f5g: Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7
Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.0 all versions, 4.0.0 through 4.2.0, 2.3.0 through 3.9.1 may allow an authenticated attacker to execute arbitrary commands in the underlying shell.
Fortinet
Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE...
vendor_fortinet·2023-01-03·CVSS 7.8
CVE-2022-35845 [HIGH] CWE-78 Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE...
FG-IR-22-274: Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE...
Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.0 all versions, 4.0.0 through 4.2.0, 2.3.0 through 3.9.1 may allow an authenticated attacker to execute arbitrary commands in the underlying shell.
CVEs: CVE-2022-35845
CWEs: CWE-78
CVSS: 7.8 (high)
Affected products: FortiTester
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-03
Published