CVE-2024-33503

A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0 all versions, FortiManager 7.4.0 throug

Severity
Medium 6.7
CVSS 3.1
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
0.002
11.0th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jan 14, 2025
Assigned by fortinet

Description

A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalation of privilege via specific shell commands

Weakness: CWE-266

Affected products

Vendor Product Category Matched by
Fortinet FortiManager Check your version Network & Security Management cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiManager Cloud
  • Fortinet · FortiManager

Credit

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security Team.

Vendor remediation

Upgrade to FortiManager Cloud version 7.4.4 or above Upgrade to FortiManager Cloud version 7.2.7 or above Upgrade to FortiAnalyzer Cloud version 7.4.3 or above Upgrade to FortiAnalyzer Cloud version 7.2.7 or above Upgrade to FortiManager version 7.6.0 or above Upgrade to FortiManager version 7.4.4 or above Upgrade to FortiManager version 7.2.6 or above Upgrade to FortiAnalyzer version 7.4.4 or above Upgrade to FortiAnalyzer version 7.2.6 or above

Something wrong here?