First published: Tue Mar 11 2025(Updated: )
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an authenticated attacker with at least read-only admin permission and CLI access to execute unauthorized code via specifically crafted CLI commands.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiIsolator | >=2.4.0<=2.4.5 |
Please upgrade to FortiIsolator version 2.4.6 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-55590 is classified as a critical vulnerability due to its potential for OS command injection.
To fix CVE-2024-55590, update Fortinet FortiIsolator to version 2.4.6 or later.
CVE-2024-55590 affects Fortinet FortiIsolator versions 2.4.0 through 2.4.5.
An authenticated attacker with read-only admin permissions and CLI access can exploit CVE-2024-55590.
CVE-2024-55590 is an OS command injection vulnerability.