Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54072 | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted packets |
Solution
Please upgrade to FortiManager version 7.6.0 or above Please upgrade to FortiManager version 7.4.4 or above Please upgrade to FortiManager Cloud version 7.4.4 or above
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-222 |
|
Fri, 25 Jul 2025 04:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet fortimanager Cloud
|
|
| CPEs | cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet fortimanager Cloud
|
Mon, 14 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 15 Mar 2025 03:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 15 Mar 2025 00:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted packets | |
| First Time appeared |
Fortinet
Fortinet fortimanager |
|
| Weaknesses | CWE-77 | |
| CPEs | cpe:2.3:o:fortinet:fortimanager:7.4.1:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortimanager:7.4.2:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortimanager:7.4.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet fortimanager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-03-15T03:55:27.259Z
Reserved: 2024-09-11T12:14:59.203Z
Link: CVE-2024-46662
Updated: 2025-03-14T17:54:06.840Z
Status : Analyzed
Published: 2025-03-14T15:15:43.200
Modified: 2025-07-24T18:49:00.753
Link: CVE-2024-46662
No data.
OpenCVE Enrichment
No data.
EUVD