CVE-2024-45331

CWE-2664 documents4 sources
Severity
7.8HIGH
EPSS
0.2%
top 60.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16

Description

A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiManager versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiAnalyzer Cloud versions 7.4.1 through 7.4.2, 7.2.1 through 7.2.6, 7.0.1 through 7.0.13, 6.4.1 through 6.4.7 allows attacker to escalate privilege via specific shell commands

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.3 | Impact: 5.9

Affected Packages6 packages

NVDfortinet/fortianalyzer_cloud6.4.17.2.7+1
NVDfortinet/fortianalyzer6.4.07.2.6+1
NVDfortinet/fortimanager_cloud7.0.17.2.7+1
CVEListV5fortinet/fortianalyzer7.4.07.4.3+3
NVDfortinet/fortimanager6.4.07.2.6+1

🔴Vulnerability Details

2
GHSA
GHSA-rjhh-4m39-v2cg: A incorrect privilege assignment in Fortinet FortiAnalyzer versions 72025-01-16
CVEList
CVE-2024-45331: A incorrect privilege assignment in Fortinet FortiAnalyzer versions 72025-01-16

📋Vendor Advisories

1
Fortinet
Multiple privilege escalation2025-01-14
CVE-2024-45331 (HIGH CVSS 7.8) | A incorrect privilege assignment in | cvebase.io