CVE-2019-15708
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
15/03/2020
Last modified:
19/03/2020
Description
A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U below 6.0.0 under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted ifconfig commands.
Impact
Base Score 3.x
6.70
Severity 3.x
MEDIUM
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:fortinet:fortiap:*:*:*:*:*:*:*:* | 6.0.5 (including) | |
| cpe:2.3:a:fortinet:fortiap-s:*:*:*:*:*:*:*:* | 6.0.5 (including) | |
| cpe:2.3:a:fortinet:fortiap-s:6.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:fortinet:fortiap-s:6.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:fortinet:fortiap-u:*:*:*:*:*:*:*:* | 6.0.0 (including) | |
| cpe:2.3:a:fortinet:fortiap-w2:*:*:*:*:*:*:*:* | 6.0.5 (including) | |
| cpe:2.3:a:fortinet:fortiap-w2:6.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:fortinet:fortiap-w2:6.2.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



