CVE-2024-56497
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiR
Description
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or commands via the CLI.
Weakness: CWE-78
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiMail | Email Security | cna-assigner |
| Fortinet | FortiRecorder | Other Products | cna-assigner |
Vendor-reported products (2)
- Fortinet · FortiMail
- Fortinet · FortiRecorder
Credit
This was discovered during an independent source code audit commissioned by Fortinet.
Vendor remediation
Please upgrade to FortiMail version 7.4.0 or above Please upgrade to FortiMail version 7.2.5 or above Please upgrade to FortiMail version 7.0.7 or above Please upgrade to FortiMail version 6.4.8 or above Please upgrade to FortiRecorder version 7.2.0 or above Please upgrade to FortiRecorder version 7.0.2 or above Please upgrade to FortiRecorder version 6.4.5 or above