CVE-2024-55590

Severity
8.8HIGH
EPSS
0.4%
top 36.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 11

Description

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an authenticated attacker with at least read-only admin permission and CLI access to execute unauthorized code via specifically crafted CLI commands.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortiisolator2.4.02.4.6
CVEListV5fortinet/fortiisolator2.4.02.4.5

🔴Vulnerability Details

2
CVEList
CVE-2024-55590: Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator2025-03-11
GHSA
GHSA-vx56-xwhw-6m46: Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator2025-03-11

📋Vendor Advisories

1
Fortinet
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE...2025-03-11
CVE-2024-55590 (HIGH CVSS 8.8) | Multiple improper neutralization of | cvebase.io