CVE-2024-33501 – Fortinet FortiAnalyzer/FortiManager/FortiAnalyzer-BigData SQL Injection

CVE ID : CVE-2024-33501

Published : March 11, 2025, 3:15 p.m. | 1 hour, 27 minutes ago

Description : Two improper neutralization of special elements used in an SQL Command (‘SQL Injection’) vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized code or commands via specifically crafted CLI requests.

Severity: 4.2 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE-2024-33501 – Fortinet FortiAnalyzer/FortiManager/FortiAnalyzer-BigData SQL Injection