CVE-2024-45331
EUVD-2024-4127616.01.2025, 09:15
A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiManager versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiAnalyzer Cloud versions 7.4.1 through 7.4.2, 7.2.1 through 7.2.6, 7.0.1 through 7.0.13, 6.4.1 through 6.4.7 allows attacker to escalate privilege via specific shell commandsEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fortinet | fortianalyzer | 6.4.0 ≤ 𝑥 < 7.2.6 |
| fortinet | fortianalyzer | 7.4.0 ≤ 𝑥 < 7.4.4 |
| fortinet | fortianalyzer_cloud | 6.4.1 ≤ 𝑥 < 7.2.7 |
| fortinet | fortianalyzer_cloud | 7.4.1 ≤ 𝑥 < 7.4.3 |
| fortinet | fortimanager | 6.4.0 ≤ 𝑥 < 7.2.6 |
| fortinet | fortimanager | 7.4.0 ≤ 𝑥 < 7.4.4 |
| fortinet | fortimanager_cloud | 7.0.1 ≤ 𝑥 < 7.2.7 |
| fortinet | fortimanager_cloud | 7.4.1 ≤ 𝑥 < 7.4.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration