CVE-2024-40587: OS Command Injection
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40587?
CVE-2024-40587 is considered a critical vulnerability due to its potential for unauthorized code execution.
How do I fix CVE-2024-40587?
To fix CVE-2024-40587, FortiVoice users should update to version 7.0.5 or later, or 6.4.10 or later.
What systems are affected by CVE-2024-40587?
CVE-2024-40587 affects Fortinet FortiVoice versions 7.0.0 through 7.0.4 and all versions before 6.4.9.
Who can exploit CVE-2024-40587?
CVE-2024-40587 can be exploited by authenticated privileged attackers who send crafted CLI requests.
What type of vulnerability is CVE-2024-40587?
CVE-2024-40587 is an OS Command Injection vulnerability that improperly neutralizes special OS command elements.