Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade to FortiSOAR on-premise version 7.6.2 or above Upgrade to FortiSOAR on-premise version 7.5.2 or above
Workaround
No workaround given by the vendor.
Link | Providers |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-412 |
![]() ![]() |
Tue, 14 Oct 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 14 Oct 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an attacker who has already obtained a non-login low privileged shell access (via another hypothetical vulnerability) to perform a local privilege escalation via crafted commands. | |
First Time appeared |
Fortinet
Fortinet fortisoaron-premise |
|
Weaknesses | CWE-78 | |
CPEs | cpe:2.3:a:fortinet:fortisoaron-premise:7.3.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaron-premise:7.3.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaron-premise:7.3.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaron-premise:7.3.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaron-premise:7.4.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaron-premise:7.4.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaron-premise:7.4.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaron-premise:7.4.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaron-premise:7.4.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaron-premise:7.4.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaron-premise:7.5.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaron-premise:7.5.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisoaron-premise:7.6.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Fortinet
Fortinet fortisoaron-premise |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-10-14T17:36:39.566Z
Reserved: 2024-10-09T09:03:09.962Z
Link: CVE-2024-48891

Updated: 2025-10-14T16:52:16.555Z

Status : Awaiting Analysis
Published: 2025-10-14T16:15:35.503
Modified: 2025-10-14T19:36:29.240
Link: CVE-2024-48891

No data.

No data.