CVE-2024-50566: OS Command Injection
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 through 7.4.4, FortiManager Cloud 7.2.2 through 7.2.7, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.0 through 7.4.5, FortiManager 7.2.1 through 7.2.8 may allow an authenticated remote attacker to execute unauthorized code via FGFM crafted requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50566?
CVE-2024-50566 is rated as critical due to its potential for remote code execution through OS command injection.
How do I fix CVE-2024-50566?
You can fix CVE-2024-50566 by upgrading Fortinet FortiManager and FortiManager Cloud to the latest patched versions.
Which versions are affected by CVE-2024-50566?
CVE-2024-50566 affects Fortinet FortiManager versions from 7.2.1 to 7.6.1 and FortiManager Cloud versions from 7.2.2 to 7.6.1.
What are the potential risks of CVE-2024-50566?
The risks include unauthorized command execution, which can lead to system compromise and data breaches.
Is there a workaround for CVE-2024-50566 if I cannot upgrade immediately?
There are currently no effective workarounds recommended for CVE-2024-50566, so upgrading is the best course of action.