An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortisiem | 6.6.0 | 6.6.3.x |
| fortinet / fortisiem | 7.1.1 | 7.1.1.x |
| fortinet / fortisiem | 7.1.0 | 7.1.0.x |
| fortinet / fortisiem | 7.0.0 | 7.0.2.x |
| fortinet / fortisiem | 6.7.0 | 6.7.8.x |
| fortinet / fortisiem | 6.5.0 | 6.5.2.x |
| fortinet / fortisiem | 6.4.0 | 6.4.2.x |