Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortiadc  >> 7.0.4  Security Vulnerabilities
An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script.
CVSS Score
8.1
EPSS Score
0.002
Published
2023-11-14
Multiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-78] in Fortinet FortiADCManager version 7.1.0 and before 7.0.0, FortiADC version 7.2.0 and before 7.1.2 allows a local authenticated attacker to execute arbitrary shell code as `root` user via crafted CLI requests.
CVSS Score
7.8
EPSS Score
0.002
Published
2023-06-13
A relative path traversal [CWE-23] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a privileged attacker to delete arbitrary directories from the underlying file system via crafted CLI commands.
CVSS Score
6.0
EPSS Score
0.001
Published
2023-05-03


Contact Us

Shodan ® - All rights reserved