CVE-2024-46662

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted packets
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*

History

24 Jul 2025, 18:49

Type Values Removed Values Added
First Time Fortinet fortimanager
Fortinet
Fortinet fortimanager Cloud
References () https://fortiguard.fortinet.com/psirt/FG-IR-24-222 - () https://fortiguard.fortinet.com/psirt/FG-IR-24-222 - Vendor Advisory
CPE cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Summary
  • (es) Una neutralización incorrecta de elementos especiales utilizados en un comando ('inyección de comando') en Fortinet FortiManager versiones 7.4.1 a 7.4.3, FortiManager Cloud versiones 7.4.1 a 7.4.3 permite a los atacantes escalar privilegios a través de paquetes específicamente manipulados.

14 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-14 15:15

Updated : 2025-07-24 18:49


NVD link : CVE-2024-46662

Mitre link : CVE-2024-46662

CVE.ORG link : CVE-2024-46662


JSON object : View

Products Affected

fortinet

  • fortimanager
  • fortimanager_cloud
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')