CVE-2024-56497: OS Command Injection
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or commands via the CLI.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56497?
CVE-2024-56497 is classified as a high-severity vulnerability due to its potential for unauthorized code execution.
How do I fix CVE-2024-56497?
To fix CVE-2024-56497, update FortiMail and FortiRecorder to their respective versions that are higher than 7.2.4, 7.0.6, and 6.4.7 for FortiMail or 6.4.4 for FortiRecorder.
What products are affected by CVE-2024-56497?
CVE-2024-56497 affects Fortinet FortiMail versions 7.2.0 to 7.2.4, 7.0.0 to 7.0.6, and 6.4.0 to 6.4.7, along with FortiRecorder versions 7.0.0 and 6.4.0 to 6.4.4.
Can CVE-2024-56497 lead to data breaches?
Yes, CVE-2024-56497 can potentially lead to data breaches as it allows attackers to execute arbitrary commands on affected systems.
What is the nature of the vulnerability CVE-2024-56497?
CVE-2024-56497 is a type of OS command injection vulnerability resulting from improper neutralization of special elements.