CVE-2024-33503

A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specific shell commands
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*

History

31 Jan 2025, 17:36

Type Values Removed Values Added
References () https://fortiguard.fortinet.com/psirt/FG-IR-24-127 - () https://fortiguard.fortinet.com/psirt/FG-IR-24-127 - Vendor Advisory
CPE cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
Summary
  • (es) Una gestión de privilegios incorrecta en Fortinet FortiManager versión 7.4.0 a 7.4.3, 7.2.0 a 7.2.5, 7.0.0 a 7.0.12, 6.4.0 a 6.4.14, FortiAnalyzer versión 7.4.0 a 7.4.2, 7.2.0 a 7.2.5, 7.0.0 a 7.0.12, 6.4.0 a 6.4.14 permite a los atacantes escalar privilegios a través de comandos de shell específicos.
First Time Fortinet fortimanager Cloud
Fortinet
Fortinet fortimanager
Fortinet fortianalyzer Cloud
Fortinet fortianalyzer

14 Jan 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-14 14:15

Updated : 2025-01-31 17:36


NVD link : CVE-2024-33503

Mitre link : CVE-2024-33503

CVE.ORG link : CVE-2024-33503


JSON object : View

Products Affected

fortinet

  • fortianalyzer
  • fortianalyzer_cloud
  • fortimanager_cloud
  • fortimanager
CWE
CWE-266

Incorrect Privilege Assignment

NVD-CWE-noinfo