imPC@ndo EN

Tracker / CVE-2024-40584

CVE-2024-40584

Alta 7.2

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiAnalyzer BigData version 7.4.0, 7.2.0 through 7.2.7, 7.0.1 through 7.0.6, 6.4.5 through 6.4.7 and 6.2.5, Fortinet FortiAnalyzer Cloud version 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.13 and 6.4.1 through 6.4.7 and Fortinet FortiManager Cloud version 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.13 and 6.4.1 through 6.4.7 GUI allows an authenticated privileged attacker to execute unauthorized code or commands via crafted HTTPS or HTTP requests.

Prodotti e versioni affette

fortinet fortianalyzer · 6.2.2 → 7.2.6
fortinet fortianalyzer · 7.4.0 → 7.4.4
fortinet fortianalyzer_big_data
fortinet fortianalyzer_big_data · 6.2.1 → 7.2.8
fortinet fortianalyzer_cloud · 6.4.1 → 7.2.6
fortinet fortianalyzer_cloud · 7.4.1 → 7.4.4
fortinet fortimanager · 6.2.2 → 6.2.13
fortinet fortimanager · 6.4.0 → 7.2.6
fortinet fortimanager · 7.4.0 → 7.4.4
fortinet fortimanager_cloud · 6.4.1 → 7.0.14
fortinet fortimanager_cloud · 7.2.1 → 7.2.6
fortinet fortimanager_cloud · 7.4.1 → 7.4.4

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti