Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jrrp-wvgf-hmfr

Опубликовано: 16 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allows attacker to execute unauthorized code or commands via specially crafted input parameters.

A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allows attacker to execute unauthorized code or commands via specially crafted input parameters.

EPSS

Процентиль: 58%
0.00363
Низкий

8.8 High

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 7.2
nvd
почти 3 года назад

A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allows attacker to execute unauthorized code or commands via specially crafted input parameters.

EPSS

Процентиль: 58%
0.00363
Низкий

8.8 High

CVSS3

Дефекты

CWE-88