CVE-2024-35273

A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*

History

31 Jan 2025, 17:38

Type Values Removed Values Added
Summary
  • (es) Una escritura fuera de los límites en Fortinet FortiManager versión 7.4.0 a 7.4.2 y FortiAnalyzer versión 7.4.0 a 7.4.2 permite a un atacante escalar privilegios a través de solicitudes http especialmente manipuladas.
References () https://fortiguard.fortinet.com/psirt/FG-IR-24-106 - () https://fortiguard.fortinet.com/psirt/FG-IR-24-106 - Vendor Advisory
First Time Fortinet
Fortinet fortimanager
Fortinet fortianalyzer Cloud
Fortinet fortimanager Cloud
Fortinet fortianalyzer
CPE cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*

14 Jan 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-14 14:15

Updated : 2025-01-31 17:38


NVD link : CVE-2024-35273

Mitre link : CVE-2024-35273

CVE.ORG link : CVE-2024-35273


JSON object : View

Products Affected

fortinet

  • fortianalyzer
  • fortimanager
  • fortimanager_cloud
  • fortianalyzer_cloud
CWE
CWE-787

Out-of-bounds Write