CVE Vulnerabilities

CVE-2024-45330

Use of Externally-Controlled Format String

Published: Oct 08, 2024 | Modified: Oct 19, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted requests.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

Name Vendor Start Version End Version
Fortianalyzer Fortinet 7.2.2 (including) 7.2.5 (including)
Fortianalyzer Fortinet 7.4.0 (including) 7.4.3 (including)
Fortianalyzer_cloud Fortinet 7.2.2 (including) 7.2.6 (including)
Fortianalyzer_cloud Fortinet 7.4.1 (including) 7.4.3 (including)

Potential Mitigations

References