CVE-2019-15708

A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U below 6.0.0 under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted ifconfig commands.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 46%
VendorProductVersion
fortinetfortiap
𝑥
≤ 6.0.5
fortinetfortiap-s
𝑥
≤ 6.0.5
fortinetfortiap-s
6.2.0
fortinetfortiap-s
6.2.1
fortinetfortiap-u
𝑥
≤ 6.0.0
fortinetfortiap-w2
𝑥
≤ 6.0.5
fortinetfortiap-w2
6.2.0
fortinetfortiap-w2
6.2.1
𝑥
= Vulnerable software versions