CVE Vulnerabilities

CVE-2024-33503

Incorrect Privilege Assignment

Published: Jan 14, 2025 | Modified: Jan 31, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specific shell commands

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
FortianalyzerFortinet6.4.0 (including)7.2.6 (excluding)
FortianalyzerFortinet7.4.0 (including)7.4.4 (excluding)
Fortianalyzer_cloudFortinet6.4.1 (including)7.2.7 (excluding)
Fortianalyzer_cloudFortinet7.4.1 (including)7.4.3 (excluding)
FortimanagerFortinet6.4.0 (including)7.2.6 (excluding)
FortimanagerFortinet7.4.0 (including)7.4.4 (excluding)
Fortimanager_cloudFortinet7.0.1 (including)7.2.7 (excluding)
Fortimanager_cloudFortinet7.4.1 (including)7.4.4 (excluding)

Potential Mitigations

References