CVE-2024-45331
published 2025-01-16CVE-2024-45331: A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all…
PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
10.3th percentile
A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, FortiAnalyzer Cloud 7.2.1 through 7.2.6, FortiAnalyzer Cloud 7.0 all versions, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalate privilege via specific shell commands
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | >= 6.4.0 < 7.2.6 | 7.2.6 |
| fortinet | fortianalyzer | 6.4.0 – 6.4.15 | — |
| fortinet | fortianalyzer | 7.0.0 – 7.0.16 | — |
| fortinet | fortianalyzer | 7.2.0 – 7.2.5 | — |
| fortinet | fortianalyzer | >= 7.4.0 < 7.4.4 | 7.4.4 |
| fortinet | fortianalyzer | 7.4.0 – 7.4.3 | — |
| fortinet | fortianalyzer_cloud | >= 6.4.1 < 7.2.7 | 7.2.7 |
| fortinet | fortianalyzer_cloud | 6.4.1 – 6.4.7 | — |
| fortinet | fortianalyzer_cloud | 7.0.1 – 7.0.16 | — |
| fortinet | fortianalyzer_cloud | 7.2.1 – 7.2.6 | — |
| fortinet | fortianalyzer_cloud | >= 7.4.1 < 7.4.3 | 7.4.3 |
| fortinet | fortianalyzer_cloud | 7.4.1 – 7.4.2 | — |
| fortinet | fortianalyzercloud | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 6.4.0 < 7.2.6 | 7.2.6 |
| fortinet | fortimanager | 6.4.0 – 6.4.15 | — |
| fortinet | fortimanager | 7.0.0 – 7.0.16 | — |
| fortinet | fortimanager | 7.2.0 – 7.2.5 | — |
| fortinet | fortimanager | >= 7.4.0 < 7.4.4 | 7.4.4 |
| fortinet | fortimanager | 7.4.0 – 7.4.2 | — |
| fortinet | fortimanager_cloud | >= 7.0.1 < 7.2.7 | 7.2.7 |
| fortinet | fortimanager_cloud | >= 7.4.1 < 7.4.4 | 7.4.4 |
| fortinet | fortimanagercloud | — | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Fortinet FortiAnalyzer/FortiManager up to 6.4.15/7.0.13/7.2.5/7.4.3 Shell Command privileges assignment (FG-IR-24-127)
vuldb·2026-07-08·CVSS 7.8
CVE-2024-45331 [HIGH] Fortinet FortiAnalyzer/FortiManager up to 6.4.15/7.0.13/7.2.5/7.4.3 Shell Command privileges assignment (FG-IR-24-127)
A vulnerability described as critical has been identified in Fortinet FortiAnalyzer and FortiManager up to 6.4.15/7.0.13/7.2.5/7.4.3. The affected element is an unknown function of the component Shell Command Handler. The manipulation results in incorrect privilege assignment.
This vulnerability is reported as CVE-2024-45331. The attack requires a local approach. No exploit exists.
GHSA
GHSA-rjhh-4m39-v2cg: A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7
ghsa_unreviewed·2025-01-16
CVE-2024-45331 [HIGH] CWE-266 GHSA-rjhh-4m39-v2cg: A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7
A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiManager versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiAnalyzer Cloud versions 7.4.1 through 7.4.2, 7.2.1 through 7.2.6, 7.0.1 through 7.0.13, 6.4.1 through 6.4.7 allows attacker to escalate privilege via specific shell commands
Fortinet
Multiple privilege escalation
vendor_fortinet·2025-01-14·CVSS 7.3
CVE-2024-33503 [MEDIUM] CWE-266 Multiple privilege escalation
FG-IR-24-127: Multiple privilege escalation
A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specific shell commands
A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiManager versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiAnalyzer Cloud versions 7.4.1 through 7.4.2, 7.2.1 through 7.2.6, 7.0.1 through 7.0.13, 6.4.1 through 6.4.7 allows attacker to escalate privilege via specific
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-16
Published