CVE-2024-48891: OS Command Injection
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an attacker who has already obtained a non-login low privileged shell access (via another hypothetical vulnerability) to perform a local privilege escalation via crafted commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48891?
CVE-2024-48891 is classified as a critical severity vulnerability due to its potential for OS command injection.
How do I fix CVE-2024-48891?
To fix CVE-2024-48891, upgrade to FortiSOAR version 7.6.2 or later.
What versions of FortiSOAR are affected by CVE-2024-48891?
CVE-2024-48891 affects FortiSOAR versions 7.6.0 through 7.6.1, 7.5.0 through 7.5.1, and all versions of 7.4 and 7.3.
What is OS Command Injection in the context of CVE-2024-48891?
OS Command Injection in CVE-2024-48891 refers to the vulnerability allowing attackers to execute arbitrary commands on the host operating system.
Who can exploit CVE-2024-48891?
CVE-2024-48891 can be exploited by attackers who have already obtained non-login low privileged shell access.