CVE-2024-33510

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 358

Summary

CVE-2024-33510 is a newly disclosed vulnerability affecting FortiOS versions 7.4.3 and below, 7.2.8 and below, and 7.0.16 and below, as well as FortiProxy versions 7.4.3 and below, 7.2.9 and below, and 7.0.16 and below, and FortiSASE version 24.2.b. The flaw involves an improper neutralization of special elements in output used by a downstream component, classified as an Injection (CWE-74) vulnerability. This issue allows a remote, unauthenticated attacker to execute phishing attempts through crafted requests, potentially leading to unauthorized access or data theft. Users are strongly encouraged to apply the available patches to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Fortinet FortiProxy
  • FortiOS

Affected Vendors

  • Fortinet