First published: Tue Jan 14 2025(Updated: )
A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiManager versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiAnalyzer Cloud versions 7.4.1 through 7.4.2, 7.2.1 through 7.2.6, 7.0.1 through 7.0.13, 6.4.1 through 6.4.7 allows attacker to escalate privilege via specific shell commands
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAnalyzer | >=7.4.0<=7.4.3 | |
Fortinet FortiAnalyzer | >=7.2.0<=7.2.5 | |
Fortinet FortiAnalyzer | >=7.0 | |
Fortinet FortiAnalyzer | >=6.4 | |
Fortinet FortiAnalyzer Cloud | >=7.4.1<=7.4.2 | |
Fortinet FortiAnalyzer Cloud | >=7.2.1<=7.2.6 | |
Fortinet FortiAnalyzer Cloud | >=7.0 | |
Fortinet FortiAnalyzer Cloud | >=6.4 | |
Fortinet FortiManager Cloud | >=7.4.1<=7.4.3 | |
Fortinet FortiManager Cloud | >=7.2.1<=7.2.5 | |
Fortinet FortiManager Cloud | >=7.0 | |
Fortinet FortiManager | >=7.4.0<=7.4.3 | |
Fortinet FortiManager | >=7.2.0<=7.2.5 | |
Fortinet FortiManager | >=7.0 | |
Fortinet FortiManager | >=6.4 | |
Fortinet FortiAnalyzer | >=6.4.0<7.2.6 | |
Fortinet FortiAnalyzer | >=7.4.0<7.4.4 | |
Fortinet FortiAnalyzer Cloud | >=6.4.1<7.2.7 | |
Fortinet FortiAnalyzer Cloud | >=7.4.1<7.4.3 | |
Fortinet FortiManager | >=6.4.0<7.2.6 | |
Fortinet FortiManager | >=7.4.0<7.4.4 | |
Fortinet FortiManager Cloud | >=7.0.1<7.2.7 | |
Fortinet FortiManager Cloud | >=7.4.1<7.4.4 |
Please upgrade to FortiAnalyzer version 7.4.4 or above Please upgrade to FortiAnalyzer version 7.2.6 or above Please upgrade to FortiManager version 7.6.0 or above Please upgrade to FortiManager version 7.4.4 or above Please upgrade to FortiManager version 7.2.6 or above Please upgrade to FortiManager Cloud version 7.4.4 or above Please upgrade to FortiManager Cloud version 7.2.7 or above Please upgrade to FortiAnalyzer Cloud version 7.4.3 or above Please upgrade to FortiAnalyzer Cloud version 7.2.7 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45331 has a high severity rating due to incorrect privilege assignment that may lead to unauthorized access.
To remediate CVE-2024-45331, you should upgrade FortiAnalyzer and FortiManager to versions 7.4.4 or 7.2.6, respectively.
Affected versions of FortiAnalyzer include 7.4.0 to 7.4.3, 7.2.0 to 7.2.5, and several others listed in the vulnerability details.
CVE-2024-45331 impacts Fortinet FortiAnalyzer, FortiManager, and FortiAnalyzer Cloud across multiple versions.
Yes, CVE-2024-45331 specifically affects Fortinet products including FortiAnalyzer and FortiManager.