CVE-2022-35849 HIGH

CVE-2022-35849

Vendor Fortinet
Product FortiADC
Weakness CWE-78
Published September 13, 2023
Last update December 16, 2025

CVSS base score

7.4/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C

What the vulnerability does

01Description

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 through 7.1.1, 7.0.0 through 7.0.3, 6.2.0 through 6.2.5 and 6.1.0 all versions may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.

Key dates

02Disclosure timeline

September 13, 2023 CVE published
December 16, 2025 Record updated