A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted packets
2025-03-14T15:15:43.200
2025-07-24T18:49:00.753
Analyzed
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortimanager | < 7.4.4 | Yes |
Application | fortinet | fortimanager_cloud | < 7.4.4 | Yes |