CVE-2024-33505

A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specially crafted http requests
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*

History

31 Jan 2025, 17:41

Type Values Removed Values Added
References () https://fortiguard.fortinet.com/psirt/FG-IR-24-125 - () https://fortiguard.fortinet.com/psirt/FG-IR-24-125 - Vendor Advisory
First Time Fortinet fortimanager Cloud
Fortinet
Fortinet fortianalyzer
Fortinet fortimanager
CPE cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
CWE CWE-787

13 Nov 2024, 17:01

Type Values Removed Values Added
Summary
  • (es) Un desbordamiento de búfer basado en montón en Fortinet FortiAnalyzer versión 7.4.0 a 7.4.2, 7.2.0 a 7.2.5, 7.0.0 a 7.0.12, 6.4.0 a 6.4.14, FortiManager versión 7.4.0 a 7.4.2, 7.2.0 a 7.2.5, 7.0.0 a 7.0.12, 6.4.0 a 6.4.14 permite a un atacante escalar privilegios a través de solicitudes http especialmente manipuladas.

12 Nov 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-12 19:15

Updated : 2025-01-31 17:41


NVD link : CVE-2024-33505

Mitre link : CVE-2024-33505

CVE.ORG link : CVE-2024-33505


JSON object : View

Products Affected

fortinet

  • fortianalyzer
  • fortimanager_cloud
  • fortimanager
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write