CVE-2024-45330: Format String Bug in fazsvcd
A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted requests.
Other sources
A use of externally-controlled format string vulnerability [CWE-134] in FortiAnalyzer fazsvcd daemon may allow a remote privileged attacker with admin profile to execute arbitrary code or commands via specially crafted requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45330?
CVE-2024-45330 has a high severity rating due to its potential for privilege escalation.
How do I fix CVE-2024-45330?
To fix CVE-2024-45330, upgrade FortiAnalyzer to version 7.4.4 or 7.2.6 and FortiAnalyzer Cloud to version 7.4.4 or 7.2.7.
What products are affected by CVE-2024-45330?
CVE-2024-45330 affects Fortinet FortiAnalyzer versions 7.4.0 to 7.4.3 and 7.2.2 to 7.2.5, as well as FortiAnalyzer Cloud in the same version ranges.
What type of vulnerability is CVE-2024-45330?
CVE-2024-45330 is classified as a use of externally-controlled format string vulnerability.
What can attackers achieve by exploiting CVE-2024-45330?
Exploiting CVE-2024-45330 allows attackers to escalate their privileges on the affected systems.