CVE-2024-55594
published 2025-03-14CVE-2024-55594: An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through…
PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.48%
38.5th percentile
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | >= 7.0.0 < 7.4.7 | 7.4.7 |
| fortinet | fortiweb | 7.0.0 – 7.0.10 | — |
| fortinet | fortiweb | 7.2.0 – 7.2.10 | — |
| fortinet | fortiweb | 7.4.0 – 7.4.6 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7...
vendor_fortinet·2025-03-11·CVSS 5.6
CVE-2023-42784 [MEDIUM] CWE-228 An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7...
FG-IR-23-115: An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7...
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.
CVEs: CVE-2023-42784, CVE-2024-55594
CWEs: CWE-228
CVSS: 5.6 (medium)
Affected products: FortiWeb, Fortinet
GHSA
GHSA-x5rc-p5hc-wc9m: An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7
ghsa_unreviewed·2025-03-14
CVE-2024-55594 [MEDIUM] CWE-228 GHSA-x5rc-p5hc-wc9m: An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-14
Published