VYPR
Medium severity6.7NVD Advisory· Published Mar 15, 2020· Updated Jun 17, 2026

CVE-2019-15708

CVE-2019-15708

Description

A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U below 6.0.0 under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted ifconfig commands.

Affected products

14
  • cpe:2.3:a:fortinet:fortiap-s:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:fortinet:fortiap-s:*:*:*:*:*:*:*:*range: <=6.0.5
    • cpe:2.3:a:fortinet:fortiap-s:6.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiap-s:6.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiap:*:*:*:*:*:*:*:*range: <=6.0.5
    • (no CPE)range: <=6.0.5
    • (no CPE)range: 6.2.1
  • cpe:2.3:a:fortinet:fortiap-u:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortiap-u:*:*:*:*:*:*:*:*range: <=6.0.0
    • (no CPE)range: <6.0.0
  • cpe:2.3:a:fortinet:fortiap-w2:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:fortinet:fortiap-w2:*:*:*:*:*:*:*:*range: <=6.0.5
    • cpe:2.3:a:fortinet:fortiap-w2:6.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortiap-w2:6.2.1:*:*:*:*:*:*:*
    • (no CPE)range: <=6.2.1
  • Fortinet/Fortinetcpe-rescue2 versions
    below 6.0.0+ 1 more
    • (no CPE)range: below 6.0.0
    • (no CPE)range: 6.0.5 and below

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.