CVE-2024-46662
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows atta
Severity
High 8.3
CVSS 3.1
Exploited
Not listed
EPSS
0.021
80.2th percentile
Discovered by
Not disclosed
Published
Mar 14, 2025
Assigned by fortinet
Description
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted packets
Weakness: CWE-77
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiManager | Network & Security Management | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiManager
Vendor remediation
Please upgrade to FortiManager version 7.6.0 or above Please upgrade to FortiManager version 7.4.4 or above Please upgrade to FortiManager Cloud version 7.4.4 or above