CVE-2024-55590: OS Command Injection
Published Mar 11, 2025
·Updated
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an authenticated attacker with at least read-only admin permission and CLI access to execute unauthorized code via specifically crafted CLI commands.
Affected Software
2 affected components
Fortinet FortiIsolator>=2.4.0<=2.4.5
Fortinet FortiIsolator>=2.4.0<2.4.6
Remediation
Information
Please upgrade to FortiIsolator version 2.4.6 or above
Event History
Mar 11, 2025
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-55590?
CVE-2024-55590 is classified as a critical vulnerability due to its potential for OS command injection.
2
How do I fix CVE-2024-55590?
To fix CVE-2024-55590, update Fortinet FortiIsolator to version 2.4.6 or later.
3
What versions of Fortinet FortiIsolator are affected by CVE-2024-55590?
CVE-2024-55590 affects Fortinet FortiIsolator versions 2.4.0 through 2.4.5.
4
Who can exploit CVE-2024-55590?
An authenticated attacker with read-only admin permissions and CLI access can exploit CVE-2024-55590.
5
What type of vulnerability is CVE-2024-55590?
CVE-2024-55590 is an OS command injection vulnerability.