An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiAnalyzer BigData version 7.4.0, 7.2.0 through 7.2.7, 7.0.1 through 7.0.6, 6.4.5 through 6.4.7 and 6.2.5, Fortinet FortiAnalyzer Cloud version 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.13 and 6.4.1 through 6.4.7 and Fortinet FortiManager Cloud version 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.13 and 6.4.1 through 6.4.7 GUI allows an authenticated privileged attacker to execute unauthorized code or commands via crafted HTTPS or HTTP requests.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-220 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
22 Jul 2025, 21:37
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortianalyzer_cloud:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortianalyzer_big_data:7.4.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortianalyzer_big_data:*:*:*:*:*:*:*:* |
|
First Time |
Fortinet fortianalyzer Cloud
Fortinet fortianalyzer Big Data Fortinet fortimanager Cloud Fortinet fortianalyzer Fortinet Fortinet fortimanager |
|
Summary |
|
|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-220 - Vendor Advisory |
11 Feb 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-11 17:15
Updated : 2025-07-22 21:37
NVD link : CVE-2024-40584
Mitre link : CVE-2024-40584
CVE.ORG link : CVE-2024-40584
JSON object : View
Products Affected
fortinet
- fortianalyzer_cloud
- fortimanager_cloud
- fortimanager
- fortianalyzer
- fortianalyzer_big_data
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')