CVE-2024-33503: Multiple privilege escalation
A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalation of privilege via specific shell commands
Other sources
An improper privilege management vulnerability [CWE 269] in FortiManager and FortiAnalyzer may allow a local attacker to escalate their privileges by abusing incorrect filesystem permissions
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiAnalyzer Cloudto a version that resolves this vulnerability.Fixed in 7.2.7 - Upgrade
Upgrade
FortiAnalyzer Cloudto a version that resolves this vulnerability.Fixed in 7.4.3 - Upgrade
Upgrade
FortiAnalyzerto a version that resolves this vulnerability.Fixed in 7.2.6 - Upgrade
Upgrade
FortiAnalyzerto a version that resolves this vulnerability.Fixed in 7.4.4 - Upgrade
Upgrade
FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.2.7 - Upgrade
Upgrade
FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.4.4 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.2.6 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.4.4 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33503?
CVE-2024-33503 has been classified with a high severity due to improper privilege management.
How do I fix CVE-2024-33503?
To mitigate CVE-2024-33503, upgrade to FortiManager version 7.4.4 or later, FortiAnalyzer version 7.4.4 or later, and their cloud counterparts as specified.
Which versions are affected by CVE-2024-33503?
CVE-2024-33503 affects Fortinet FortiManager versions 7.4.0 to 7.4.3, and various earlier versions of FortiAnalyzer.
Is there a workaround for CVE-2024-33503?
There is no confirmed workaround for CVE-2024-33503; the recommended solution is to upgrade to the patched versions.
Who is impacted by CVE-2024-33503?
Organizations using affected versions of Fortinet FortiManager and FortiAnalyzer platforms are vulnerable to CVE-2024-33503.