7.8
CVE-2024-33503
- EPSS 0.03%
- Veröffentlicht 14.01.2025 14:15:29
- Zuletzt bearbeitet 31.01.2025 17:36:27
- Quelle psirt@fortinet.com
- CVE-Watchlists
- Unerledigt
A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specific shell commands
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortianalyzer Version >= 6.4.0 < 7.2.6
Fortinet ≫ Fortianalyzer Version >= 7.4.0 < 7.4.4
Fortinet ≫ Fortianalyzer Cloud Version >= 6.4.1 < 7.2.7
Fortinet ≫ Fortianalyzer Cloud Version >= 7.4.1 < 7.4.3
Fortinet ≫ Fortimanager Version >= 6.4.0 < 7.2.6
Fortinet ≫ Fortimanager Version >= 7.4.0 < 7.4.4
Fortinet ≫ Fortimanager Cloud Version >= 7.0.1 < 7.2.7
Fortinet ≫ Fortimanager Cloud Version >= 7.4.1 < 7.4.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.061 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| psirt@fortinet.com | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-266 Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.