CVE-2024-33508Command Injection in Fortinet Forticlient Enterprise Management Server

CWE-77Command Injection4 documents4 sources
Severity
7.3HIGHNVD
EPSS
1.6%
top 18.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 10

Description

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages2 packages

CVEListV5fortinet/forticlientems7.2.07.2.4+1

🔴Vulnerability Details

2
CVEList
CVE-2024-33508: An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 72024-09-10
GHSA
GHSA-jr6g-3qr2-xfh3: An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 72024-09-10

📋Vendor Advisories

1
Fortinet
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortine...2024-09-10
CVE-2024-33508 — Command Injection in Fortinet | cvebase