ZeroHour

CVE-2021-26116

CVSS 3.1
8.8 high
EPSS
<1%p48
Published
()
Modified
Description

An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.

Vendors
fortinet
Products
fortiauthenticator
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.