CVE-2024-40584: OS command injection in external connector
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiAnalyzer, FortiManager, FortiAnalyzer BigData, FortiAnalyzer Cloud and FortiManager Cloud GUI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted HTTPS or HTTP requests.
Other sources
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiAnalyzer BigData version 7.4.0, 7.2.0 through 7.2.7, 7.0.1 through 7.0.6, 6.4.5 through 6.4.7 and 6.2.5, Fortinet FortiAnalyzer Cloud version 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.13 and 6.4.1 through 6.4.7 and Fortinet FortiManager Cloud version 7.4.1 through 7.4.3, 7.2.1 through 7.2.5, 7.0.1 through 7.0.13 and 6.4.1 through 6.4.7 GUI allows an authenticated privileged attacker to execute unauthorized code or commands via crafted HTTPS or HTTP requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40584?
CVE-2024-40584 is classified as a critical severity vulnerability due to the potential for OS command injection.
How do I fix CVE-2024-40584?
To resolve CVE-2024-40584, it is recommended to upgrade FortiAnalyzer and FortiManager to the latest versions provided by Fortinet.
Which versions of Fortinet products are affected by CVE-2024-40584?
CVE-2024-40584 affects Fortinet FortiAnalyzer and FortiManager versions between 6.2.2 and 7.4.3.
What can happen if CVE-2024-40584 is exploited?
Exploitation of CVE-2024-40584 could allow an attacker to execute arbitrary OS commands on the affected systems.
Is CVE-2024-40584 being actively exploited in the wild?
There is currently no public information indicating that CVE-2024-40584 is being actively exploited in the wild.