CVE-2019-15708

A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U below 6.0.0 under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted ifconfig commands.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-19-209 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiap:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiap-s:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiap-s:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiap-s:6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiap-u:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiap-w2:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiap-w2:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiap-w2:6.2.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-03-15 23:15

Updated : 2024-02-28 17:47


NVD link : CVE-2019-15708

Mitre link : CVE-2019-15708

CVE.ORG link : CVE-2019-15708


JSON object : View

Products Affected

fortinet

  • fortiap-u
  • fortiap-s
  • fortiap-w2
  • fortiap
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')