imPC@ndo IT

Tracker / CVE-2021-26104

CVE-2021-26104

High 7.8

Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, FortiAnalyzer 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, and FortiPortal 5.2.5 and below, 5.3.5 and below and 6.0.4 and below may allow a local authenticated and unprivileged user to execute arbitrary shell commands as root via specifically crafted CLI command parameters.

Affected products and versions

fortinet fortianalyzer · 5.6.0 → 6.0.11
fortinet fortianalyzer · 6.2.0 → 6.2.8
fortinet fortianalyzer · 6.4.0 → 6.4.6
fortinet fortimanager · 5.6.0 → 6.0.11
fortinet fortimanager · 6.2.0 → 6.2.8
fortinet fortimanager · 6.4.0 → 6.4.6
fortinet fortiportal · … → 5.2.6
fortinet fortiportal · 5.3.0 → 5.3.6
fortinet fortiportal · 6.0.0 → 6.0.5

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References