An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-123 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
20 Sep 2024, 19:48
Type | Values Removed | Values Added |
---|---|---|
First Time |
Fortinet
Fortinet forticlient Enterprise Management Server |
|
CPE | cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:* | |
References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-123 - Vendor Advisory | |
Summary |
|
10 Sep 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-10 15:15
Updated : 2024-09-20 19:48
NVD link : CVE-2024-33508
Mitre link : CVE-2024-33508
CVE.ORG link : CVE-2024-33508
JSON object : View
Products Affected
fortinet
- forticlient_enterprise_management_server
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')