CVE-2022-39947
published 2023-01-03CVE-2022-39947: A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiADC version…
PriorityP264high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.89%
85.3th percentile
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiADC version 6.2.0 through 6.2.3, FortiADC version version 6.1.0 through 6.1.6, FortiADC version 6.0.0 through 6.0.4, FortiADC version 5.4.0 through 5.4.5 may allow an attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | 5.4.0 – 5.4.5 | — |
| fortinet | fortiadc | 6.0.0 – 6.0.4 | — |
| fortinet | fortiadc | 6.1.0 – 6.1.6 | — |
| fortinet | fortiadc | 6.2.0 – 6.2.3 | — |
| fortinet | fortiadc | 7.0.0 – 7.0.2 | — |
| fortinet | fortinet | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect OS command injection attempts against FortiADC via crafted HTTP requests targeting the management interface ↗
- →Monitor FortiADC versions 5.4.0–5.4.5, 6.0.0–6.0.4, 6.1.0–6.1.6, 6.2.0–6.2.3, and 7.0.0–7.0.2 for anomalous HTTP requests containing shell metacharacters or command injection payloads (CWE-78) ↗
- ·Vulnerability is exploitable by an authenticated attacker (CVSS 8.8 implies authentication required); restrict management interface access and enforce least-privilege accounts on FortiADC ↗
- ·All FortiADC branches from 5.4 through 7.0 are affected; ensure patching covers all deployed branches (5.4.x, 6.0.x, 6.1.x, 6.2.x, 7.0.x) ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC versio...
vendor_fortinet·2023-01-03·CVSS 8.8
CVE-2022-39947 [HIGH] CWE-78 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC versio...
FG-IR-22-061: A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC versio...
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiADC version 6.2.0 through 6.2.3, FortiADC version version 6.1.0 through 6.1.6, FortiADC version 6.0.0 through 6.0.4, FortiADC version 5.4.0 through 5.4.5 may allow an attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CVEs: CVE-2022-39947
CWEs: CWE-78
CVSS: 8.8 (high)
Affected products: FortiADC, Fortinet
GHSA
GHSA-83pc-v7mg-rhvg: A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7
ghsa_unreviewed·2023-01-03
CVE-2022-39947 [HIGH] CWE-78 GHSA-83pc-v7mg-rhvg: A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiADC version 6.2.0 through 6.2.3, FortiADC version version 6.1.0 through 6.1.6, FortiADC version 6.0.0 through 6.0.4, FortiADC version 5.4.0 through 5.4.5 may allow an attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-03
Published