A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and below, 4.1.7 and below allows an authenticated attacker to execute privileged shell commands via CLI commands including special characters
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://fortiguard.com/advisory/FG-IR-21-148 |     | 
History
                    Fri, 25 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: fortinet
Published: 2022-02-02T10:58:37
Updated: 2024-10-25T13:36:06.405Z
Reserved: 2021-09-13T00:00:00
Link: CVE-2021-41016
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-04T02:59:31.059Z
 NVD
                        NVD
                    Status : Modified
Published: 2022-02-02T11:15:07.777
Modified: 2024-11-21T06:25:16.133
Link: CVE-2021-41016
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow