PT-2024-9818 · Fortinet · Forticlientems

Published

2024-09-10

·

Updated

2024-09-20

·

CVE-2024-33508

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Fortinet FortiClientEMS versions 7.0.0 through 7.0.12 Fortinet FortiClientEMS versions 7.2.0 through 7.2.4
Description: The issue is related to an improper neutralization of special elements used in a command, also known as a 'Command Injection' vulnerability. This may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.
Recommendations: For Fortinet FortiClientEMS versions 7.0.0 through 7.0.12, update to a version that addresses the Command Injection vulnerability. For Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, update to a version that addresses the Command Injection vulnerability. As a temporary workaround, consider restricting access to the underlying database to minimize the risk of exploitation.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-11594
CVE-2024-33508

Affected Products

Forticlientems