First published: Tue Jan 14 2025(Updated: )
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiManager csfd daemon may allow an authenticated attacker to execute unauthorized commands via specifically crafted packets
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiManager Cloud | >=7.4.1<=7.4.3 | |
Fortinet FortiManager | >=7.4.1<=7.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-46662 is classified as a critical vulnerability due to its potential for unauthorized command execution.
To remediate CVE-2024-46662, update FortiManager or FortiManager Cloud to version 7.4.4 or later.
CVE-2024-46662 affects Fortinet FortiManager and Fortinet FortiManager Cloud versions between 7.4.1 and 7.4.3.
Yes, CVE-2024-46662 can be exploited by an authenticated attacker through specially crafted packets.
CVE-2024-46662 involves an improper neutralization of special elements used in an operating system command, aligning with CWE-78.