OS Command Injection Vulnerability in Fortinet FortiManager
CVE-2024-50566
7.2HIGH
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 14 January 2025
What is CVE-2024-50566?
An OS command injection vulnerability exists in Fortinet FortiManager that allows an authenticated remote attacker to execute unauthorized commands by crafting specific FGFM requests. This vulnerability affects multiple versions of both FortiManager and FortiManager Cloud, presenting significant security risks if not addressed promptly. Organizations using vulnerable versions should apply the recommended patches to safeguard against potential exploits.
Affected Version(s)
FortiManager 7.6.0 <= 7.6.1
FortiManager 7.4.0 <= 7.4.5
FortiManager 7.2.1 <= 7.2.8