A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager versions 7.6.0 through 7.6.1, versions 7.4.5 through 7.4.0, and versions 7.2.1 through 7.2.8, FortiManager Cloud versions 7.6.0 through 7.6.1, versions 7.4.0 through 7.4.4, and versions 7.2.2 through 7.2.7 may allow an authenticated remote attacker to execute unauthorized code via FGFM crafted requests.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-463 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
03 Feb 2025, 22:09
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* |
|
First Time |
Fortinet fortimanager
Fortinet Fortinet fortimanager Cloud |
|
Summary |
|
|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-463 - Vendor Advisory |
14 Jan 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-14 14:15
Updated : 2025-02-03 22:09
NVD link : CVE-2024-50566
Mitre link : CVE-2024-50566
CVE.ORG link : CVE-2024-50566
JSON object : View
Products Affected
fortinet
- fortimanager
- fortimanager_cloud
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')