CVE-2024-33503

CWE-2664 documents4 sources
Severity
7.8HIGH
EPSS
0.0%
top 91.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14

Description

A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specific shell commands

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages5 packages

NVDfortinet/fortimanager6.4.07.2.6+1
NVDfortinet/fortianalyzer6.4.07.2.6+1
NVDfortinet/fortimanager_cloud7.0.17.2.7+1
NVDfortinet/fortianalyzer_cloud6.4.17.2.7+1
CVEListV5fortinet/fortimanager7.4.07.4.3+3

🔴Vulnerability Details

2
CVEList
CVE-2024-33503: A improper privilege management in Fortinet FortiManager version 72025-01-14
GHSA
GHSA-hw72-fmxv-278r: A improper privilege management in Fortinet FortiManager version 72025-01-14

📋Vendor Advisories

1
Fortinet
Multiple privilege escalation2025-01-14
CVE-2024-33503 (HIGH CVSS 7.8) | A improper privilege management in | cvebase.io