CVE-2024-33503
published 2025-01-14CVE-2024-33503: A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.4th percentile
A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalation of privilege via specific shell commands
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | >= 6.4.0 < 7.2.6 | 7.2.6 |
| fortinet | fortianalyzer | >= 7.4.0 < 7.4.4 | 7.4.4 |
| fortinet | fortianalyzer_cloud | >= 6.4.1 < 7.2.7 | 7.2.7 |
| fortinet | fortianalyzer_cloud | >= 7.4.1 < 7.4.3 | 7.4.3 |
| fortinet | fortianalyzercloud | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 6.4.0 < 7.2.6 | 7.2.6 |
| fortinet | fortimanager | 6.4.0 – 6.4.15 | — |
| fortinet | fortimanager | 7.0.0 – 7.0.16 | — |
| fortinet | fortimanager | 7.2.0 – 7.2.5 | — |
| fortinet | fortimanager | >= 7.4.0 < 7.4.4 | 7.4.4 |
| fortinet | fortimanager | 7.4.0 – 7.4.3 | — |
| fortinet | fortimanager_cloud | >= 7.0.1 < 7.2.7 | 7.2.7 |
| fortinet | fortimanager_cloud | 7.0.1 – 7.0.13 | — |
| fortinet | fortimanager_cloud | 7.2.1 – 7.2.6 | — |
| fortinet | fortimanager_cloud | >= 7.4.1 < 7.4.4 | 7.4.4 |
| fortinet | fortimanager_cloud | 7.4.1 – 7.4.3 | — |
| fortinet | fortimanagercloud | — | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Fortinet FortiManager up to 6.4.15/7.0.13/7.2.5/7.4.3 privileges assignment (FG-IR-24-127)
vuldb·2026-07-08·CVSS 7.8
CVE-2024-33503 [HIGH] Fortinet FortiManager up to 6.4.15/7.0.13/7.2.5/7.4.3 privileges assignment (FG-IR-24-127)
A vulnerability, which was classified as critical, was found in Fortinet FortiManager up to 6.4.15/7.0.13/7.2.5/7.4.3. Impacted is an unknown function. Executing a manipulation can lead to incorrect privilege assignment.
This vulnerability appears as CVE-2024-33503. The attack requires local access. There is no available exploit.
GHSA
GHSA-hw72-fmxv-278r: A improper privilege management in Fortinet FortiManager version 7
ghsa_unreviewed·2025-01-14
CVE-2024-33503 [MEDIUM] CWE-266 GHSA-hw72-fmxv-278r: A improper privilege management in Fortinet FortiManager version 7
A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specific shell commands
Fortinet
Multiple privilege escalation
vendor_fortinet·2025-01-14·CVSS 7.3
CVE-2024-33503 [MEDIUM] CWE-266 Multiple privilege escalation
FG-IR-24-127: Multiple privilege escalation
A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specific shell commands
A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiManager versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiAnalyzer Cloud versions 7.4.1 through 7.4.2, 7.2.1 through 7.2.6, 7.0.1 through 7.0.13, 6.4.1 through 6.4.7 allows attacker to escalate privilege via specific
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-14
Published