CVE-2024-56497
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiR
Description
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or commands via the CLI.
Weakness: CWE-78
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiMail | Email Security | cna-assigner |
| Fortinet | FortiRecorder | Other Products | cna-assigner |
Vendor-reported affected versions (2)
- Fortinet · FortiMail
- Fortinet · FortiRecorder
Vendor remediation
Please upgrade to FortiMail version 7.4.0 or above Please upgrade to FortiMail version 7.2.5 or above Please upgrade to FortiMail version 7.0.7 or above Please upgrade to FortiMail version 6.4.8 or above Please upgrade to FortiRecorder version 7.2.0 or above Please upgrade to FortiRecorder version 7.0.2 or above Please upgrade to FortiRecorder version 6.4.5 or above