CVE-2024-40587
14.01.2025, 14:15
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.
Vendor | Product | Version |
---|---|---|
fortinet | fortivoice | 6.0.0 ≤ 𝑥 < 6.4.10 |
fortinet | fortivoice | 7.0.0 ≤ 𝑥 < 7.0.5 |
𝑥
= Vulnerable software versions