CVE-2024-33501
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD
Description
Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized code or commands via specifically crafted CLI requests.
Affected (7)
Products: Fortinet: Fortianalyzer, Fortianalyzer Big Data, Fortimanager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.4.0 to 7.2.6 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.4.5 to 7.2.8 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.0.10 to 6.0.12 |
References (1)
Timeline
No history available yet.