VYPR
High severity7.8NVD Advisory· Published Nov 2, 2022· Updated Jun 17, 2026

CVE-2022-33870

CVE-2022-33870

Description

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiTester 3.0.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.

Affected products

22
  • cpe:2.3:a:fortinet:fortitester:3.0.0:*:*:*:*:*:*:*+ 20 more
    • cpe:2.3:a:fortinet:fortitester:3.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:3.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:3.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:3.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:3.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:3.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:3.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:3.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:3.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:3.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:3.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:3.8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:3.9.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:3.9.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:4.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:4.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:4.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:4.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:7.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortitester:7.1.0:*:*:*:*:*:*:*
    • (no CPE)range: 3.0.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0
  • Fortinet/Fortinetcpe-rescue
    Range: FortiTester 3.0.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.