CVE Vulnerabilities

CVE-2024-33510

Improperly Implemented Security Check for Standard

Published: Nov 12, 2024 | Modified: Jan 17, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

AnĀ improper neutralization of special elements in output used by a downstream component (Injection) vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below; FortiSASE version 24.2.b SSL-VPN web user interface may allow a remote unauthenticated attacker to perform phishing attempts via crafted requests.

Weakness

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

Affected Software

NameVendorStart VersionEnd Version
FortiproxyFortinet7.0.0 (including)7.0.17 (excluding)
FortiproxyFortinet7.2.0 (including)7.2.10 (excluding)
FortiproxyFortinet7.4.0 (including)7.4.4 (excluding)
FortiosFortinet7.0.0 (including)7.2.9 (excluding)
FortiosFortinet7.4.0 (including)7.4.4 (excluding)

References