FortiManager 7.6.0, FortiManager 7.4.0부터 7.4.4까지, FortiManager 7.2.0부터 7.2.7까지, FortiManager 7.0.0부터 7.0.12까지, FortiManager 6.4.0부터 6.4.14까지, FortiManager 6.2.0부터 6.2.12까지, Fortinet FortiManager Cloud 7.4.1부터 7.4.4까지, FortiManager Cloud 7.2.1부터 7.2.7까지, FortiManager Cloud 7.0.1부터 7.0.12까지, FortiManager Cloud 6.4.1부터 6.4.7까지에 존재하는 중요 기능에 대한 인증 누락으로 인해 공격자가 특별히 조작된 요청을 통해 임의의 코드 또는 명령을 실행할 수 있습니다.
FortiManager 7.6.0, FortiManager 7.4.0부터 7.4.4까지, FortiManager 7.2.0부터 7.2.7까지, FortiManager 7.0.0부터 7.0.12까지, FortiManager 6.4.0부터 6.4.14까지, FortiManager 6.2.0부터 6.2.12까지, Fortinet FortiManager Cloud 7.4.1부터 7.4.4까지, FortiManager Cloud 7.2.1부터 7.2.7까지, FortiManager Cloud 7.0.1부터 7.0.12까지, FortiManager Cloud 6.4.1부터 6.4.7까지에 존재하는 중요 기능에 대한 인증 누락으로 인해 공격자가 특별히 조작된 요청을 통해 임의의 코드 또는 명령을 실행할 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.