CVE-2024-45331: Multiple privilege escalation
A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, FortiAnalyzer Cloud 7.2.1 through 7.2.6, FortiAnalyzer Cloud 7.0 all versions, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalate privilege via specific shell commands
Other sources
An improper privilege management vulnerability [CWE 269] in FortiManager and FortiAnalyzer may allow a local attacker to escalate their privileges by abusing incorrect filesystem permissions
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiAnalyzer Cloudto a version that resolves this vulnerability.Fixed in 7.2.7 - Upgrade
Upgrade
FortiAnalyzer Cloudto a version that resolves this vulnerability.Fixed in 7.4.3 - Upgrade
Upgrade
FortiAnalyzerto a version that resolves this vulnerability.Fixed in 7.2.6 - Upgrade
Upgrade
FortiAnalyzerto a version that resolves this vulnerability.Fixed in 7.4.4 - Upgrade
Upgrade
FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.2.7 - Upgrade
Upgrade
FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.4.4 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.2.6 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.4.4 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45331?
CVE-2024-45331 has a high severity rating due to incorrect privilege assignment that may lead to unauthorized access.
How do I fix CVE-2024-45331?
To remediate CVE-2024-45331, you should upgrade FortiAnalyzer and FortiManager to versions 7.4.4 or 7.2.6, respectively.
Which versions are affected by CVE-2024-45331?
Affected versions of FortiAnalyzer include 7.4.0 to 7.4.3, 7.2.0 to 7.2.5, and several others listed in the vulnerability details.
What products are impacted by CVE-2024-45331?
CVE-2024-45331 impacts Fortinet FortiAnalyzer, FortiManager, and FortiAnalyzer Cloud across multiple versions.
Is CVE-2024-45331 specific to Fortinet products?
Yes, CVE-2024-45331 specifically affects Fortinet products including FortiAnalyzer and FortiManager.