High
CVE-2022-35845
Fortinet FortiTester could allow a local authenticated attacker to execute arbitrary commands on the system, caused by an OS command injection flaw in GUI and API. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands in the underlying shell.
Fortinet
Refer to Fortinet Security Advisory for patch, upgrade or suggested workaround information.