CVE-2024-45331
Last modified
CVE-2024-45331 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, FortiAnalyzer Cloud 7.2.1 through 7.2.6, FortiAnalyzer Cloud 7.0 all versions, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalate privilege via specific shell commands. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, FortiAnalyzer Cloud 7.2.1 through 7.2.6, FortiAnalyzer Cloud 7.0 all versions, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalate privilege via specific shell commands
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortianalyzer | >= 6.4.0, < 7.2.6 |
| Fortinet | Fortianalyzer | >= 7.4.0, < 7.4.4 |
| Fortinet | Fortianalyzer Cloud | >= 6.4.1, < 7.2.7 |
| Fortinet | Fortianalyzer Cloud | >= 7.4.1, < 7.4.3 |
| Fortinet | Fortimanager | >= 6.4.0, < 7.2.6 |
| Fortinet | Fortimanager | >= 7.4.0, < 7.4.4 |
| Fortinet | Fortimanager Cloud | >= 7.0.1, < 7.2.7 |
| Fortinet | Fortimanager Cloud | >= 7.4.1, < 7.4.4 |
References
- https://fortiguard.fortinet.com/psirt/FG-IR-24-127Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-45331?
How severe is CVE-2024-45331?
How do I fix CVE-2024-45331?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45326An Improper Access Control vulnerability [CWE-284] vulnerabi…4.3
- CVE-2024-45327An improper authorization vulnerability [CWE-285] in FortiSO…7.5
- CVE-2024-45328An incorrect authorization vulnerability [CWE-863] in FortiS…7.8
- CVE-2024-45329A authorization bypass through user-controlled key in Fortin…4.3
- CVE-2024-4533The KKProgressbar2 Free WordPress plugin through 1.1.4.2 do…6.5
- CVE-2024-45330A use of externally-controlled format string in Fortinet For…7.2
- CVE-2024-45332Exposure of sensitive information caused by shared microarch…5.7
- CVE-2024-45333Improper access control for some Intel(R) Data Center GPU Fl…7.3
- CVE-2024-45334Trend Micro Antivirus One versions 3.10.4 and below (Consume…7.8
- CVE-2024-45335Trend Micro Antivirus One, version 3.10.4 and below contains…5.5
- CVE-2024-45336The HTTP client drops sensitive headers after following a cr…6.1
- CVE-2024-45337Applications and libraries which misuse connection.serverAut…9.1
Are you affected by CVE-2024-45331?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
