CVE-2024-45331

Summary

A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, FortiAnalyzer Cloud 7.2.1 through 7.2.6, FortiAnalyzer Cloud 7.0 all versions, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalate privilege via specific shell commands

Affected Software

VendorProductVersion RangeStatus
FortinetFortiAnalyzer Cloud7.4.1 <= 7.4.2affected
FortinetFortiAnalyzer Cloud7.2.1 <= 7.2.6affected
FortinetFortiAnalyzer Cloud7.0.1 <= 7.0.16affected
FortinetFortiAnalyzer Cloud6.4.1 <= 6.4.7affected
FortinetFortiManager7.4.0 <= 7.4.2affected
FortinetFortiManager7.2.0 <= 7.2.5affected
FortinetFortiManager7.0.0 <= 7.0.16affected
FortinetFortiManager6.4.0 <= 6.4.15affected
FortinetFortiAnalyzer7.4.0 <= 7.4.3affected
FortinetFortiAnalyzer7.2.0 <= 7.2.5affected
FortinetFortiAnalyzer7.0.0 <= 7.0.16affected
FortinetFortiAnalyzer6.4.0 <= 6.4.15affected

Weaknesses

  • CWE-266: Escalation of privilege

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References