CVE-2024-40587
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Published Jan 14, 2025
CWE ID 78
Summary
CVE-2024-40587 is a critical OS Command Injection vulnerability affecting Fortinet FortiVoice versions 7.0.0 through 7.0.4 and older 6.4.9. This issue permits authenticated privileged attackers to execute unauthorized code or commands by exploiting improper handling of special elements in Crafted CLI requests. The vulnerability, identified as CWE-78, can potentially lead to serious security implications. Fortinet urges users to promptly update their systems to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Fortinet