← Back

CVE-2024-48891

nvd nist
Published: Oct 14, 2025Modified: Oct 15, 2025

JSON object

Loading...
7.0
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.0 / Impact: 5.9
Source: NVD

Description

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an attacker who has already obtained a non-login low privileged shell access (via another hypothetical vulnerability) to perform a local privilege escalation via crafted commands.

Affected (2)

Products: Fortinet: Fortisoar
1 product
Fortisoar
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 7.3.0 to 7.5.2
From 7.6.0 to 7.6.2

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.