CVE-2024-48890

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated atta

Severity
Medium 6.3
CVSS 3.1
Exploited
Not listed
EPSS
0.011
64.8th percentile
Discovered by
Third party
Vendor advisory field
Published
Jan 14, 2025
Assigned by fortinet

Description

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook

Weakness: CWE-78

Affected products

Vendor Product Category Matched by
Fortinet FortiSOAR SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiSOAR

Credit

Fortinet is pleased to thank Lexfo company for reporting this vulnerability under responsible disclosure.

Vendor remediation

Please upgrade to FortiSOAR version 7.5.1 or above

Something wrong here?