ZeroHour

CVE-2016-4965

CVSS 3.0
8.8 high
EPSS
4%p90
Published
()
Modified
Description

Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup functionality to execute arbitrary commands with root privileges via the graph parameter to diagnosis_control.php.

Vendors
fortinet
Products
fortiwan
Weakness
CWE-78
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.