CVE-2024-32123

Severity
6.7MEDIUM
EPSS
0.0%
top 86.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 11

Description

Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 and 5.6.0 through 5.6.11 and 5.4.0 through 5.4.7 and 5.2.0 through 5.2.10 and 5.0.0 through 5.0.12 and 4.3.4 through 4.3.8 allows attacker to execute unauthorized code or commands via crafted CLI requests.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages5 packages

NVDfortinet/fortimanager4.3.47.2.6+1
NVDfortinet/fortianalyzer6.2.07.2.6+1
NVDfortinet/fortianalyzer_big_data6.4.57.2.8+1
CVEListV5fortinet/fortimanager7.4.07.4.2+10
CVEListV5fortinet/fortianalyzer7.4.07.4.2+4

🔴Vulnerability Details

2
GHSA
GHSA-j9mc-f96q-8ch7: Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 72025-03-11
CVEList
CVE-2024-32123: Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 72025-03-11

📋Vendor Advisories

1
Fortinet
OS command injection in CLI command2025-03-11
CVE-2024-32123 (MEDIUM CVSS 6.7) | Multiple improper neutralization of | cvebase.io