CVE-2024-45331

A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAn

Severity
Medium 6.9
CVSS 3.1
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
0.002
9.9th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jan 16, 2025
Assigned by fortinet

Description

A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, FortiAnalyzer Cloud 7.2.1 through 7.2.6, FortiAnalyzer Cloud 7.0 all versions, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalate privilege via specific shell commands

Weakness: CWE-266

Affected products

Vendor Product Category Matched by
Fortinet FortiAnalyzer Check your version SIEM & Log Management cna-assigner
Fortinet FortiManager Check your version Network & Security Management cna-assigner
Vendor-reported products (3)
  • Fortinet · FortiAnalyzer Cloud
  • Fortinet · FortiManager
  • Fortinet · FortiAnalyzer

Credit

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security Team.

Vendor remediation

Upgrade to FortiManager Cloud version 7.4.4 or above Upgrade to FortiManager Cloud version 7.2.7 or above Upgrade to FortiAnalyzer Cloud version 7.4.3 or above Upgrade to FortiAnalyzer Cloud version 7.2.7 or above Upgrade to FortiManager version 7.6.0 or above Upgrade to FortiManager version 7.4.4 or above Upgrade to FortiManager version 7.2.6 or above Upgrade to FortiAnalyzer version 7.4.4 or above Upgrade to FortiAnalyzer version 7.2.6 or above

Something wrong here?