CVE-2024-33508: Command Injection
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33508?
CVE-2024-33508 is considered a critical severity vulnerability that can allow unauthorized command execution.
How do I fix CVE-2024-33508?
To fix CVE-2024-33508, update Fortinet FortiClient EMS to versions 7.2.5 or later, or 7.0.13 or later.
Who is affected by CVE-2024-33508?
CVE-2024-33508 affects Fortinet FortiClient EMS versions 7.2.0 to 7.2.4 and 7.0.0 to 7.0.12.
What types of operations can be executed due to CVE-2024-33508?
CVE-2024-33508 allows an unauthenticated attacker to execute limited and temporary operations on the underlying database.
What is the nature of the vulnerability described in CVE-2024-33508?
CVE-2024-33508 is a command injection vulnerability that involves improper neutralization of special elements.