CVE-2024-33508 — Command Injection in Fortinet Forticlient Enterprise Management Server
Severity
7.3HIGHNVD
EPSS
1.6%
top 18.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 10
Description
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4
Affected Packages2 packages
🔴Vulnerability Details
2CVEList▶
CVE-2024-33508: An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7↗2024-09-10
GHSA▶
GHSA-jr6g-3qr2-xfh3: An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7↗2024-09-10
📋Vendor Advisories
1Fortinet▶
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortine...↗2024-09-10