CVE-2024-33508

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthen

Severity
Medium 6.9
CVSS 3.1
Exploited
Not listed
EPSS
0.013
68.9th percentile
Discovered by
Third party
Vendor advisory field
Published
Sep 10, 2024
Assigned by fortinet

Description

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.

Weakness: CWE-77

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiClientEMS
  • fortinet · forticlient_endpoint_management_server

Credit

Fortinet is pleased to thank ANSSI for reporting this vulnerability under responsible disclosure.

Vendor remediation

Please upgrade to FortiSASE version 24.2.c or above Please upgrade to FortiClientEMS version 7.4.0 or above Please upgrade to FortiClientEMS version 7.2.5 or above Please upgrade to FortiClientEMS version 7.0.13 or above

Something wrong here?