CVE-2024-55590
published 2025-03-11CVE-2024-55590: Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version…
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.04%
60.0th percentile
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an authenticated attacker with at least read-only admin permission and CLI access to execute unauthorized code via specifically crafted CLI commands.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiisolator | — | — |
| fortinet | fortiisolator | >= 2.4.0 < 2.4.6 | 2.4.6 |
| fortinet | fortiisolator | 2.4.0 – 2.4.5 | — |
| fortinet | fortinet | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for OS command injection attempts via CLI commands on FortiIsolator, particularly from accounts with read-only admin privileges or higher ↗
- →Audit CLI access logs on FortiIsolator versions 2.4.0 through 2.4.5 for anomalous or specially crafted command sequences indicative of OS command injection (CWE-78) ↗
- ·Exploitation requires authentication with at least read-only admin permission AND CLI access; attack surface is limited to users with CLI-level access to the device ↗
- ·All FortiIsolator versions from 2.4.0 through 2.4.5 are affected; deployments should be assessed for version exposure ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vx56-xwhw-6m46: Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator
ghsa_unreviewed·2025-03-11
CVE-2024-55590 [HIGH] CWE-78 GHSA-vx56-xwhw-6m46: Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an authenticated attacker with at least read-only admin permission and CLI access to execute unauthorized code via specifically crafted CLI commands.
Fortinet
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE...
vendor_fortinet·2025-03-11·CVSS 8.8
CVE-2024-55590 [HIGH] CWE-78 Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE...
FG-IR-24-178: Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE...
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an authenticated attacker with at least read-only admin permission and CLI access to execute unauthorized code via specifically crafted CLI commands.
CVEs: CVE-2024-55590
CWEs: CWE-78
CVSS: 8.8 (high)
Affected products: FortiIsolator, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-11
Published