Medium severity6.7NVD Advisory· Published Apr 11, 2023· Updated Jun 17, 2026
CVE-2022-43948
CVE-2022-43948
Description
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.3, FortiADC version 7.1.0 through 7.1.1, FortiADC version 7.0.0 through 7.0.3, FortiADC 6.2 all versions, FortiADC 6.1 all versions, FortiADC 6.0 all versions, FortiADC 5.4 all versions, FortiADC 5.3 all versions, FortiADC 5.2 all versions, FortiADC 5.1 all versions allows attacker to execute unauthorized code or commands via specifically crafted arguments to existing commands.
Affected products
6cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*range: >=5.1.0,<6.2.6
- (no CPE)range: 7.1.0
- Range: 7.1.0 - 7.1.1, 7.0.0 - 7.0.3, 6.2, 6.1, 6.0, 5.4, 5.3, 5.2, 5.1
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-186nvdVendor Advisory
News mentions
0No linked articles in our index yet.