PSIRT Advisories

FortiWLM - command Injection in script handlers

Summary

An improper neutralization of special elements used in an OS command ('OS Command Injection') [CWE-78] vulnerability in FortiWLM may allow an authenticated attacker to execute arbitrary shell commands via crafted HTTP requests to the alarm dashboard and controller config handlers.

Affected Products

FortiWLM version 8.6.2 and below
FortiWLM version 8.5.2 and below
FortiWLM version 8.4.2 and below

Solutions

Upgrade to FortiWLM version 8.6.3 or above.

Acknowledgement

Internally discovered and reported by Mattia Fecit of Fortinet Product Security Team.