CVE Vulnerabilities

CVE-2024-33503

Incorrect Privilege Assignment

Published: Jan 14, 2025 | Modified: Jan 31, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specific shell commands

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Fortianalyzer Fortinet 6.4.0 (including) 7.2.6 (excluding)
Fortianalyzer Fortinet 7.4.0 (including) 7.4.4 (excluding)
Fortianalyzer_cloud Fortinet 6.4.1 (including) 7.2.7 (excluding)
Fortianalyzer_cloud Fortinet 7.4.1 (including) 7.4.3 (excluding)
Fortimanager Fortinet 6.4.0 (including) 7.2.6 (excluding)
Fortimanager Fortinet 7.4.0 (including) 7.4.4 (excluding)
Fortimanager_cloud Fortinet 7.0.1 (including) 7.2.7 (excluding)
Fortimanager_cloud Fortinet 7.4.1 (including) 7.4.4 (excluding)

Potential Mitigations

References