Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-48889


An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.4 and below, version 7.2.7 and below, version 7.0.12 and below, version 6.4.14 and below and FortiManager Cloud version 7.4.4 and below, version 7.2.7 to 7.2.1, version 7.0.12 to 7.0.1 may allow an authenticated remote attacker to execute unauthorized code via FGFM crafted requests.


Published

2024-12-18T13:15:06.463

Last Modified

2025-07-23T15:04:55.817

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-78
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortimanager < 6.4.15 Yes
Application fortinet fortimanager < 7.0.13 Yes
Application fortinet fortimanager < 7.2.8 Yes
Application fortinet fortimanager < 7.4.5 Yes
Application fortinet fortimanager 7.6.0 Yes
Application fortinet fortimanager_cloud < 7.0.13 Yes
Application fortinet fortimanager_cloud < 7.2.8 Yes
Application fortinet fortimanager_cloud < 7.4.5 Yes

References