CVE-2024-52962

An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and below and FortiManager version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.12 and below may allow an unauthenticated remote attacker to pollute the logs via crafted login requests.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*

History

23 Jul 2025, 16:02

Type Values Removed Values Added
References () https://fortiguard.fortinet.com/psirt/FG-IR-24-453 - () https://fortiguard.fortinet.com/psirt/FG-IR-24-453 - Vendor Advisory
CPE cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
First Time Fortinet fortianalyzer
Fortinet
Fortinet fortimanager

08 Apr 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 14:15

Updated : 2025-07-23 16:02


NVD link : CVE-2024-52962

Mitre link : CVE-2024-52962


JSON object : View

Products Affected

fortinet

  • fortianalyzer
  • fortimanager
CWE
CWE-117

Improper Output Neutralization for Logs