CVE-2024-33501
CVSS 3.1 Score 4.2 of 10 (medium)
Details
Published Mar 11, 2025
CWE ID 89
Summary
CVE-2024-33501 is a critical SQL Injection vulnerability affecting Fortinet's FortiAnalyzer versions 7.2.5 and later through 7.4.2, FortiManager versions 7.2.5 and later through 7.4.2, and FortiAnalyzer-BigData version 7.2.7 and earlier. This issue arises due to improper neutralization of special elements used in SQL commands. An attacker with privileged access can exploit this vulnerability (CWE-89) by delivering specifically crafted CLI requests to execute unauthorized code or commands, potentially leading to significant security compromise.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- FortiManager
Affected Vendors
- Fortinet