First published: Tue Mar 11 2025(Updated: )
Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiAnalyzer, FortiManager & FortiAnalyzer-BigData may allow a privileged attacker to execute unauthorized code or commands via specifically crafted CLI requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAnalyzer | >=7.4.0<7.4.2<7.2.5 | |
Fortinet FortiManager | >=7.4.0<7.4.2<7.2.5 | |
Fortinet FortiAnalyzer | >=7.4.0<7.4.0<7.2.7 | |
Fortinet FortiAnalyzer | >=7.4.0<=7.4.2 | |
Fortinet FortiAnalyzer | >=7.2.0<=7.2.5 | |
Fortinet FortiAnalyzer | >=7.0 | |
Fortinet FortiAnalyzer | >=6.4 | |
Fortinet FortiAnalyzer | =. | |
Fortinet FortiAnalyzer | >=7.2.0<=7.2.7 | |
Fortinet FortiAnalyzer | >=7.0 | |
Fortinet FortiAnalyzer | >=6.4 | |
Fortinet FortiManager | >=7.4.0<=7.4.2 | |
Fortinet FortiManager | >=7.2.0<=7.2.5 | |
Fortinet FortiManager | >=7.0 | |
Fortinet FortiManager | >=6.4 | |
Fortinet FortiManager | >=6.2.8<=6.2.13 | |
Fortinet FortiManager | >=6.0.10<=6.0.12 |
Please upgrade to FortiAnalyzer version 7.4.3 or above Please upgrade to FortiAnalyzer version 7.2.6 or above Please upgrade to FortiAnalyzer-BigData version 7.4.1 or above Please upgrade to FortiAnalyzer-BigData version 7.2.8 or above Please upgrade to FortiManager version 7.4.3 or above Please upgrade to FortiManager version 7.2.6 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33501 has been classified as a high severity SQL injection vulnerability that could allow unauthorized command execution.
To remediate CVE-2024-33501, upgrade FortiAnalyzer or FortiManager to versions 7.4.3 or later, or 7.2.6 or later, depending on your product.
The affected products include FortiAnalyzer, FortiManager, and FortiAnalyzer-BigData versions prior to 7.4.3 and 7.2.6.
Yes, a privileged attacker can exploit CVE-2024-33501 remotely via specially crafted CLI requests.
CVE-2024-33501 impacts Fortinet products such as FortiAnalyzer, FortiManager, and FortiAnalyzer-BigData.