Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31246 | An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests. |
Solution
Please upgrade to FortiSASE version 24.2.c or above Please upgrade to FortiClientEMS version 7.4.0 or above Please upgrade to FortiClientEMS version 7.2.5 or above Please upgrade to FortiClientEMS version 7.0.13 or above
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-123 |
|
Fri, 20 Sep 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet forticlient Enterprise Management Server
|
|
| CPEs | cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet forticlient Enterprise Management Server
|
Tue, 10 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet forticlient Endpoint Management Server |
|
| CPEs | cpe:2.3:a:fortinet:forticlient_endpoint_management_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet forticlient Endpoint Management Server |
|
| Metrics |
ssvc
|
Tue, 10 Sep 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests. | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-09-10T17:32:21.879Z
Reserved: 2024-04-23T14:18:29.830Z
Link: CVE-2024-33508
Updated: 2024-09-10T17:32:17.734Z
Status : Analyzed
Published: 2024-09-10T15:15:16.187
Modified: 2024-09-20T19:48:06.197
Link: CVE-2024-33508
No data.
OpenCVE Enrichment
No data.
EUVD