First published: Tue Jan 14 2025(Updated: )
A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specific shell commands
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAnalyzer | >=7.4.0<=7.4.3 | |
Fortinet FortiAnalyzer | >=7.2.0<=7.2.5 | |
Fortinet FortiAnalyzer | >=7.0 | |
Fortinet FortiAnalyzer | >=6.4 | |
Fortinet FortiAnalyzer Cloud | >=7.4.1<=7.4.2 | |
Fortinet FortiAnalyzer Cloud | >=7.2.1<=7.2.6 | |
Fortinet FortiAnalyzer Cloud | >=7.0 | |
Fortinet FortiAnalyzer Cloud | >=6.4 | |
Fortinet FortiManager Cloud | >=7.4.1<=7.4.3 | |
Fortinet FortiManager Cloud | >=7.2.1<=7.2.5 | |
Fortinet FortiManager Cloud | >=7.0 | |
Fortinet FortiManager | >=7.4.0<=7.4.3 | |
Fortinet FortiManager | >=7.2.0<=7.2.5 | |
Fortinet FortiManager | >=7.0 | |
Fortinet FortiManager | >=6.4 | |
Fortinet FortiAnalyzer | >=6.4.0<7.2.6 | |
Fortinet FortiAnalyzer | >=7.4.0<7.4.4 | |
Fortinet FortiAnalyzer Cloud | >=6.4.1<7.2.7 | |
Fortinet FortiAnalyzer Cloud | >=7.4.1<7.4.3 | |
Fortinet FortiManager | >=6.4.0<7.2.6 | |
Fortinet FortiManager | >=7.4.0<7.4.4 | |
Fortinet FortiManager Cloud | >=7.0.1<7.2.7 | |
Fortinet FortiManager Cloud | >=7.4.1<7.4.4 |
Please upgrade to FortiAnalyzer version 7.4.4 or above Please upgrade to FortiAnalyzer version 7.2.6 or above Please upgrade to FortiManager version 7.6.0 or above Please upgrade to FortiManager version 7.4.4 or above Please upgrade to FortiManager version 7.2.6 or above Please upgrade to FortiManager Cloud version 7.4.4 or above Please upgrade to FortiManager Cloud version 7.2.7 or above Please upgrade to FortiAnalyzer Cloud version 7.4.3 or above Please upgrade to FortiAnalyzer Cloud version 7.2.7 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33503 has been classified with a high severity due to improper privilege management.
To mitigate CVE-2024-33503, upgrade to FortiManager version 7.4.4 or later, FortiAnalyzer version 7.4.4 or later, and their cloud counterparts as specified.
CVE-2024-33503 affects Fortinet FortiManager versions 7.4.0 to 7.4.3, and various earlier versions of FortiAnalyzer.
There is no confirmed workaround for CVE-2024-33503; the recommended solution is to upgrade to the patched versions.
Organizations using affected versions of Fortinet FortiManager and FortiAnalyzer platforms are vulnerable to CVE-2024-33503.