CVE-2019-15708

EUVD-2019-6644
A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U below 6.0.0 under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted ifconfig commands.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
Affected Products (NVD)
VendorProductVersion
fortinetfortiap
𝑥
≤ 6.0.5
fortinetfortiap-s
𝑥
≤ 6.0.5
fortinetfortiap-s
6.2.0
fortinetfortiap-s
6.2.1
fortinetfortiap-u
𝑥
≤ 6.0.0
fortinetfortiap-w2
𝑥
≤ 6.0.5
fortinetfortiap-w2
6.2.0
fortinetfortiap-w2
6.2.1
𝑥
= Vulnerable software versions