CVE-2024-45325
published 2025-09-09CVE-2024-45325: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F version 7.0.0…
PriorityP340medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.48%
38.1th percentile
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F version 7.0.0 through 7.02 and before 6.6.3 may allow a privileged attacker to execute unauthorized code or commands via crafted CLI requests.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiddos | — | — |
| fortinet | fortiddos-f | — | — |
| fortinet | fortiddos-f | >= 6.1.0 < 7.0.3 | 7.0.3 |
| fortinet | fortiddos-f | 6.1.0 – 6.1.5 | — |
| fortinet | fortiddos-f | 6.2.0 – 6.2.3 | — |
| fortinet | fortiddos-f | 6.3.0 – 6.3.5 | — |
| fortinet | fortiddos-f | 6.4.0 – 6.4.2 | — |
| fortinet | fortiddos-f | 6.5.0 – 6.5.1 | — |
| fortinet | fortiddos-f | 6.6.0 – 6.6.3 | — |
| fortinet | fortiddos-f | 7.0.0 – 7.0.2 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] i...
vendor_fortinet·2025-09-09·CVSS 6.7
CVE-2024-45325 [MEDIUM] CWE-78 An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] i...
FG-IR-24-344: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] i...
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F version 7.0.0 through 7.02 and before 6.6.3 may allow a privileged attacker to execute unauthorized code or commands via crafted CLI requests.
CVEs: CVE-2024-45325
CWEs: CWE-78
CVSS: 6.7 (medium)
Affected products: FortiDDoS, FortiDdos-f, Fortinet
GHSA
GHSA-p6hc-mjhv-54c9: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F version
ghsa_unreviewed·2025-09-09
CVE-2024-45325 [MEDIUM] CWE-78 GHSA-p6hc-mjhv-54c9: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F version
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F version 7.0.0 through 7.02 and before 6.6.3 may allow a privileged attacker to execute unauthorized code or commands via crafted CLI requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-09
Published