CVE-2024-45331
6.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Summary
A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, FortiAnalyzer Cloud 7.2.1 through 7.2.6, FortiAnalyzer Cloud 7.0 all versions, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalate privilege via specific shell commands
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Fortinet | FortiAnalyzer Cloud | 7.4.1 <= 7.4.2 | affected |
| Fortinet | FortiAnalyzer Cloud | 7.2.1 <= 7.2.6 | affected |
| Fortinet | FortiAnalyzer Cloud | 7.0.1 <= 7.0.16 | affected |
| Fortinet | FortiAnalyzer Cloud | 6.4.1 <= 6.4.7 | affected |
| Fortinet | FortiManager | 7.4.0 <= 7.4.2 | affected |
| Fortinet | FortiManager | 7.2.0 <= 7.2.5 | affected |
| Fortinet | FortiManager | 7.0.0 <= 7.0.16 | affected |
| Fortinet | FortiManager | 6.4.0 <= 6.4.15 | affected |
| Fortinet | FortiAnalyzer | 7.4.0 <= 7.4.3 | affected |
| Fortinet | FortiAnalyzer | 7.2.0 <= 7.2.5 | affected |
| Fortinet | FortiAnalyzer | 7.0.0 <= 7.0.16 | affected |
| Fortinet | FortiAnalyzer | 6.4.0 <= 6.4.15 | affected |
Weaknesses
- CWE-266: Escalation of privilege
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.