OS command injection in external connector

Summary

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiAnalyzer, FortiManager, FortiAnalyzer BigData, FortiAnalyzer Cloud and FortiManager Cloud GUI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted HTTPS or HTTP requests.

Version Affected Solution
FortiAnalyzer 7.6 Not affected Not Applicable
FortiAnalyzer 7.4 7.4.0 through 7.4.3 Upgrade to 7.4.4 or above
FortiAnalyzer 7.2 7.2.0 through 7.2.5 Upgrade to 7.2.6 or above
FortiAnalyzer 7.0 7.0 all versions Migrate to a fixed release
FortiAnalyzer 6.4 6.4 all versions Migrate to a fixed release
FortiAnalyzer 6.2 6.2.2 through 6.2.13 Migrate to a fixed release
FortiAnalyzer Cloud 7.6 Not affected Not Applicable
FortiAnalyzer Cloud 7.4 7.4.1 through 7.4.3 Upgrade to 7.4.4 or above
FortiAnalyzer Cloud 7.2 7.2.1 through 7.2.5 Upgrade to 7.2.6 or above
FortiAnalyzer Cloud 7.0 7.0 all versions Migrate to a fixed release
FortiAnalyzer Cloud 6.4 6.4 all versions Migrate to a fixed release
FortiAnalyzer-BigData 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiAnalyzer-BigData 7.2 7.2.0 through 7.2.7 Upgrade to 7.2.8 or above
FortiAnalyzer-BigData 7.0 7.0 all versions Migrate to a fixed release
FortiAnalyzer-BigData 6.4 6.4 all versions Migrate to a fixed release
FortiAnalyzer-BigData 6.2 6.2 all versions Migrate to a fixed release
FortiManager 7.6 Not affected Not Applicable
FortiManager 7.4 7.4.0 through 7.4.3 Upgrade to 7.4.4 or above
FortiManager 7.2 7.2.0 through 7.2.5 Upgrade to 7.2.6 or above
FortiManager 7.0 7.0 all versions Migrate to a fixed release
FortiManager 6.4 6.4 all versions Migrate to a fixed release
FortiManager 6.2 6.2.2 through 6.2.13 Migrate to a fixed release
FortiManager Cloud 7.6 Not affected Not Applicable
FortiManager Cloud 7.4 7.4.1 through 7.4.3 Upgrade to 7.4.4 or above
FortiManager Cloud 7.2 7.2.1 through 7.2.5 Upgrade to 7.2.6 or above
FortiManager Cloud 7.0 7.0.1 through 7.0.13 Migrate to a fixed release
FortiManager Cloud 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Theo Leleu of Fortinet Product Security team.

Timeline

2025-02-11: Initial publication