CVE-2019-15708

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
15/03/2020
Last modified:
19/03/2020

Description

A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U below 6.0.0 under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted ifconfig commands.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiap:*:*:*:*:*:*:*:* 6.0.5 (including)
cpe:2.3:a:fortinet:fortiap-s:*:*:*:*:*:*:*:* 6.0.5 (including)
cpe:2.3:a:fortinet:fortiap-s:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiap-s:6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiap-u:*:*:*:*:*:*:*:* 6.0.0 (including)
cpe:2.3:a:fortinet:fortiap-w2:*:*:*:*:*:*:*:* 6.0.5 (including)
cpe:2.3:a:fortinet:fortiap-w2:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiap-w2:6.2.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools