CVE-2024-45324

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 134

Summary

CVE-2024-45324 is a format string vulnerability affecting multiple FortiOS and FortiProxy versions, FortiPAM, FortiSRA, and FortiWeb. This issue, classified as CWE-134, enables privileged attackers to inject and execute unauthorized code or commands through specially crafted HTTP or HTTPS requests. FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.9, and earlier versions, as well as FortiProxy versions 7.4.0 through 7.4.6, 7.2.0 through 7.2.12, and older versions, FortiPAM versions 1.4.0 through 1.4.2, and FortiSRA versions 1.4.0 through 1.4.2, and versions before 1.3.1, and FortiWeb versions 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.10, are all impacted.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share