CVE-2024-33501
11.03.2025, 15:15
Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attackerto execute unauthorized code or commands via specifically crafted CLI requests.
Vendor | Product | Version |
---|---|---|
fortinet | fortianalyzer | 6.4.0 ≤ 𝑥 < 7.2.6 |
fortinet | fortianalyzer | 7.4.0 ≤ 𝑥 < 7.4.3 |
fortinet | fortianalyzer_big_data | 6.4.5 ≤ 𝑥 < 7.2.8 |
fortinet | fortianalyzer_big_data | 7.4.0 |
fortinet | fortimanager | 6.0.10 ≤ 𝑥 ≤ 6.0.12 |
fortinet | fortimanager | 6.2.8 ≤ 𝑥 < 7.2.6 |
fortinet | fortimanager | 7.4.0 ≤ 𝑥 < 7.4.3 |
𝑥
= Vulnerable software versions