CVE-2019-15709

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
01/06/2020
Last modified:
03/06/2020

Description

An improper input validation in FortiAP-S/W2 6.2.0 to 6.2.2, 6.0.5 and below, FortiAP-U 6.0.1 and below CLI admin console may allow unauthorized administrators to overwrite system files via specially crafted tcpdump commands in the CLI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:fortinet:fortiap-s:*:*:*:*:*:*:*:* 6.0.5 (including)
cpe:2.3:o:fortinet:fortiap-s:*:*:*:*:*:*:*:* 6.2.0 (including) 6.2.2 (including)
cpe:2.3:h:fortinet:fortiap-s:-:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortiap-w2:*:*:*:*:*:*:*:* 6.0.5 (including)
cpe:2.3:o:fortinet:fortiap-w2:*:*:*:*:*:*:*:* 6.2.0 (including) 6.2.2 (including)
cpe:2.3:o:fortinet:fortiap-w2:-:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortiap-u:*:*:*:*:*:*:*:* 6.0.1 (including)
cpe:2.3:h:fortinet:fortiap-u:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools