CVE-2024-33510: SSLVPN WEB UI Text injection
An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS and FortiProxy SSL-VPN web user interface may allow a remote unauthenticated attacker to perform phishing attempts via crafted requests.
Other sources
An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below; FortiSASE version 24.2.b SSL-VPN web user interface may allow a remote unauthenticated attacker to perform phishing attempts via crafted requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33510?
CVE-2024-33510 has a high severity rating due to its potential for remote exploitation and phishing attacks.
How do I fix CVE-2024-33510?
To fix CVE-2024-33510, upgrade FortiOS to version 7.4.4, 7.2.9, or higher as specified in the advisory.
Which Fortinet products are affected by CVE-2024-33510?
CVE-2024-33510 affects Fortinet's FortiOS and FortiProxy products, specifically within certain version ranges.
Can CVE-2024-33510 be exploited remotely?
Yes, CVE-2024-33510 can be exploited remotely by unauthenticated attackers via specially crafted requests.
What type of vulnerability is CVE-2024-33510?
CVE-2024-33510 is classified as an improper neutralization of special elements in output, leading to injection vulnerabilities.