CVE-2019-15708

MEDIUM

FortiAP < 6.0.5 and FortiAP-U < 6.0.0 - Authenticated OS Command Injection via ifconfig Command

Title source: llm
STIX 2.1

Description

A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U below 6.0.0 under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted ifconfig commands.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/psirt/FG-IR-19-209

Scores

CVSS v3 6.7
EPSS 0.0023
EPSS Percentile 46.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (8)
fortinet/fortiap < 6.0.5
fortinet/fortiap-s 6.2.0
fortinet/fortiap-s 6.2.1
fortinet/fortiap-s < 6.0.5
fortinet/fortiap-u < 6.0.0
fortinet/fortiap-w2 6.2.0
fortinet/fortiap-w2 6.2.1
fortinet/fortiap-w2 < 6.0.5
Published Mar 15, 2020
Tracked Since Feb 18, 2026