Home
LOW: 3.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N/E:P/RL:X/RC:XDefault status
unaffected
7.2.0 (semver)
affected
7.0.0 (semver)
affected
2.0.0 (semver)
affected
1.2.0 (semver)
affected
1.1.0 (semver)
affected
Default status
unaffected
7.2.0 (semver)
affected
7.0.0 (semver)
affected
6.4.0 (semver)
affected
6.2.0 (semver)
affected
Description
An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.
Problem types
Product status
7.2.0 (semver)
7.0.0 (semver)
2.0.0 (semver)
1.2.0 (semver)
1.1.0 (semver)
7.2.0 (semver)
7.0.0 (semver)
6.4.0 (semver)
6.2.0 (semver)
References
fortiguard.fortinet.com/psirt/FG-IR-23-008