CVE-2024-48890
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated atta
Severity
Medium 6.3
CVSS 3.1
Exploited
Not listed
EPSS
0.011
64.8th percentile
Discovered by
Third party
Vendor advisory field
Published
Jan 14, 2025
Assigned by fortinet
Description
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook
Weakness: CWE-78
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSOAR | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiSOAR
Credit
Fortinet is pleased to thank Lexfo company for reporting this vulnerability under responsible disclosure.
Vendor remediation
Please upgrade to FortiSOAR version 7.5.1 or above