A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted packets
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-222 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
24 Jul 2025, 18:49
Type | Values Removed | Values Added |
---|---|---|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-222 - Vendor Advisory | |
CPE | cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* |
|
First Time |
Fortinet fortimanager Cloud
Fortinet Fortinet fortimanager |
14 Mar 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-14 15:15
Updated : 2025-07-24 18:49
NVD link : CVE-2024-46662
Mitre link : CVE-2024-46662
JSON object : View
Products Affected
fortinet
- fortimanager_cloud
- fortimanager
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')