Fiche vulnérabilité
CVE-2024-35275 : faille élevée fortinet fortianalyzer (CVSS 8.8)
Description
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 14 janv. 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- fortinet fortianalyzer
- fortinet fortianalyzer cloud
- fortinet fortimanager
- fortinet fortimanager cloud