Fortinet Fortimanager Cloud vulnerabilities

28 known vulnerabilities affecting fortinet/fortimanager_cloud.

Total CVEs
28
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH17MEDIUM4LOW2

Vulnerabilities

Page 2 of 2
CVE-2024-33503HIGHCVSS 7.8≥ 7.0.1, < 7.2.7≥ 7.4.1, < 7.4.42025-01-14
CVE-2024-33503 [HIGH] CWE-266 CVE-2024-33503: A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specific shell commands
nvd
CVE-2024-35273HIGHCVSS 8.8≥ 7.4.1, < 7.4.32025-01-14
CVE-2024-35273 [HIGH] CWE-787 CVE-2024-35273: A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7. A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.
nvd
CVE-2024-50566HIGHCVSS 8.8≥ 7.2.2, < 7.2.8≥ 7.4.0, < 7.4.5+3 more2025-01-14
CVE-2024-50566 [HIGH] CWE-78 CVE-2024-50566: A improper neutralization of special elements used in an os command ('os command injection') vulnera A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 through 7.4.4, FortiManager Cloud 7.2.2 through 7.2.7, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.0 through 7.4.5, FortiManager 7.2.1 through 7.2.8 may allow an a
cvelistv5nvd
CVE-2024-35275HIGHCVSS 8.8≥ 7.4.1, < 7.4.32025-01-14
CVE-2024-35275 [HIGH] CWE-89 CVE-2024-35275: A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet F A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.
nvd
CVE-2024-35277HIGHCVSS 7.5≥ 7.0.1, < 7.0.13≥ 7.2.1, < 7.2.7+1 more2025-01-14
CVE-2024-35277 [HIGH] CWE-306 CVE-2024-35277: A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the managed devices by sending specifically crafted packets
nvd
CVE-2024-48889HIGHCVSS 7.2≥ 7.0.1, < 7.0.13≥ 7.2.1, < 7.2.8+1 more2024-12-18
CVE-2024-48889 [HIGH] CWE-78 CVE-2024-48889: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.4 and below, version 7.2.7 and below, version 7.0.12 and below, version 6.4.14 and below and FortiManager Cloud version 7.4.4 and below, version 7.2.7 to 7.2.1, version 7.0.12 to 7.0.1 may allow
nvd
CVE-2024-33505HIGHCVSS 7.3≥ 6.4.1, < 7.2.7≥ 7.4.1, < 7.4.32024-11-12
CVE-2024-33505 [HIGH] CWE-122 CVE-2024-33505: A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7. A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specially crafted http requests
nvd
CVE-2024-47575CRITICALCVSS 9.8KEVPoC≥ 6.4.1, ≤ 6.4.7≥ 7.0.1, < 7.0.13+2 more2024-10-23
CVE-2024-47575 [CRITICAL] CWE-306 CVE-2024-47575: A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4 A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Clou
nvd