CVE-2024-33508 MEDIUM

CVE-2024-33508

Vendor Fortinet
Product FortiClientEMS
Weakness CWE-77
Published September 10, 2024
Last update September 10, 2024

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C

What the vulnerability does

01Description

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.

Key dates

02Disclosure timeline

September 10, 2024 CVE published
September 10, 2024 Record updated