CVE-2024-48889

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Dec 18, 2024
CWE ID 78

Summary

CVE-2024-48889 is a critical OS Command Injection vulnerability affecting FortiManager versions 7.6.0, 7.4.4 and below, 7.2.7 and below, 7.0.12 and below, 6.4.14 and below, and FortiManager Cloud versions 7.4.4 and below, 7.2.7 to 7.2.1, and 7.0.12 to 7.0.1. This issue stems from improper neutralization of special elements in OS commands, as per Common Vulnerabilities and Exposures (CWE) category 78. An attacker who is already authenticated can exploit this vulnerability by crafting malicious FGFM requests, potentially leading to unauthorized code execution.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share