cbcvebase.
CVE-2024-33503
published 2025-01-14

CVE-2024-33503: A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specific shell commands

Affected

17 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer>= 6.4.0 < 7.2.67.2.6
fortinetfortianalyzer>= 7.4.0 < 7.4.47.4.4
fortinetfortianalyzer_cloud>= 6.4.1 < 7.2.77.2.7
fortinetfortianalyzer_cloud>= 7.4.1 < 7.4.37.4.3
fortinetfortianalyzercloud
fortinetfortimanager
fortinetfortimanager>= 6.4.0 < 7.2.67.2.6
fortinetfortimanager6.4.0 – 6.4.15
fortinetfortimanager7.0.0 – 7.0.13
fortinetfortimanager7.2.0 – 7.2.5
fortinetfortimanager>= 7.4.0 < 7.4.47.4.4
fortinetfortimanager7.4.0 – 7.4.3
fortinetfortimanager_cloud>= 7.0.1 < 7.2.77.2.7
fortinetfortimanager_cloud>= 7.4.1 < 7.4.47.4.4
fortinetfortimanagercloud
fortinetfortinet