cbcvebase.
CVE-2024-40584
published 2025-02-11

CVE-2024-40584: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0…

high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiAnalyzer BigData version 7.4.0, 7.2.0 through 7.2.7, 7.0.1 through 7.0.6, 6.4.5 through 6.4.7 and 6.2.5, Fortinet FortiAnalyzer Cloud version 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.13 and 6.4.1 through 6.4.7 and Fortinet FortiManager Cloud version 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.13 and 6.4.1 through 6.4.7 GUI allows an authenticated privileged attacker to execute unauthorized code or commands via crafted HTTPS or HTTP requests.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer>= 6.2.2 < 7.2.67.2.6
fortinetfortianalyzer6.2.2 – 6.2.13
fortinetfortianalyzer6.4.0 – 6.4.15
fortinetfortianalyzer7.0.0 – 7.0.13
fortinetfortianalyzer7.2.0 – 7.2.5
fortinetfortianalyzer>= 7.4.0 < 7.4.47.4.4
fortinetfortianalyzer7.4.0 – 7.4.3
fortinetfortianalyzer_big_data
fortinetfortianalyzer_big_data>= 6.2.1 < 7.2.87.2.8
fortinetfortianalyzer_cloud>= 6.4.1 < 7.2.67.2.6
fortinetfortianalyzer_cloud>= 7.4.1 < 7.4.47.4.4
fortinetfortianalyzerbigdata
fortinetfortianalyzercloud
fortinetfortimanager
fortinetfortimanager6.2.2 – 6.2.13
fortinetfortimanager>= 6.4.0 < 7.2.67.2.6
fortinetfortimanager6.4.0 – 6.4.15
fortinetfortimanager7.0.0 – 7.0.13
fortinetfortimanager7.2.0 – 7.2.5
fortinetfortimanager>= 7.4.0 < 7.4.47.4.4
fortinetfortimanager7.4.0 – 7.4.3
fortinetfortimanager_cloud6.4.1 – 7.0.14
fortinetfortimanager_cloud>= 7.2.1 < 7.2.67.2.6
fortinetfortimanager_cloud>= 7.4.1 < 7.4.47.4.4