CVE-2024-32118: OS command injection in CLI command
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiManager, FortiAnalyzer & FortiAnalyzer-BigData CLI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.
Other sources
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer-BigData before 7.4.0 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32118?
CVE-2024-32118 is classified as a high severity vulnerability due to its potential for unauthorized command execution.
How do I fix CVE-2024-32118?
To fix CVE-2024-32118, upgrade FortiManager and FortiAnalyzer to version 7.4.3 or 7.2.6, respectively.
Which products are affected by CVE-2024-32118?
CVE-2024-32118 affects FortiManager and FortiAnalyzer versions 7.4.0 to 7.4.2 and 7.2.0 to 7.2.5.
Can an unauthenticated user exploit CVE-2024-32118?
No, an authenticated privileged user is required to exploit CVE-2024-32118.
What type of vulnerability is CVE-2024-32118?
CVE-2024-32118 is an OS command injection vulnerability, which allows executing unauthorized commands.