VYPR
Medium severity6.7NVD Advisory· Published Oct 18, 2022· Updated Jun 17, 2026

CVE-2022-35844

CVE-2022-35844

Description

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to commands of the certificate import feature.

Affected products

3
  • cpe:2.3:a:fortinet:fortitester:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortitester:*:*:*:*:*:*:*:*range: >=2.3.0,<3.9.2
    • (no CPE)range: 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0
  • Fortinet/Fortinetcpe-rescue
    Range: FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.