SQL Injection Vulnerability in Fortinet FortiAnalyzer and FortiManager
CVE-2024-33501
What is CVE-2024-33501?
A vulnerability in Fortinet's FortiAnalyzer, FortiManager, and FortiAnalyzer-BigData products arises from improper neutralization of special elements used in SQL commands. This security flaw enables a privileged attacker to execute unauthorized code or commands through specially crafted command-line interface (CLI) requests, potentially compromising the integrity of the affected systems. Users of versions 7.4.0 to 7.4.2 and earlier versions of FortiAnalyzer and FortiManager, as well as earlier versions of FortiAnalyzer-BigData, should take immediate measures to assess their exposure and apply the necessary patches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FortiManager 7.4.0 <= 7.4.2
FortiManager 7.2.0 <= 7.2.5
FortiManager 7.0.0 <= 7.0.13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved