CVE-2024-33510
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-33510 is a newly disclosed vulnerability affecting FortiOS versions 7.4.3 and below, 7.2.8 and below, and 7.0.16 and below, as well as FortiProxy versions 7.4.3 and below, 7.2.9 and below, and 7.0.16 and below, and FortiSASE version 24.2.b. The flaw involves an improper neutralization of special elements in output used by a downstream component, classified as an Injection (CWE-74) vulnerability. This issue allows a remote, unauthenticated attacker to execute phishing attempts through crafted requests, potentially leading to unauthorized access or data theft. Users are strongly encouraged to apply the available patches to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Fortinet FortiProxy
- FortiOS
Affected Vendors
- Fortinet