CVE-2024-46662
Published: 14 March 2025
Description
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Security Summary
CVE-2024-46662 is a command injection vulnerability (CWE-77), resulting from improper neutralization of special elements used in a command, affecting Fortinet FortiManager versions 7.4.1 through 7.4.3 and FortiManager Cloud versions 7.4.1 through 7.4.3. The issue, published on 2025-03-14T15:15:43.200, carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and enables privilege escalation via specifically crafted packets.
An attacker requires low privileges (PR:L) to exploit this vulnerability over the network (AV:N) with low attack complexity (AC:L) and no user interaction (UI:N). Successful exploitation allows the attacker to achieve high impacts on confidentiality, integrity, and availability (C:I:A:H), specifically through privilege escalation.
The Fortinet advisory FG-IR-24-222 at https://fortiguard.fortinet.com/psirt/FG-IR-24-222 provides details on mitigation and patching recommendations for affected versions.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Command injection vulnerability in FortiManager directly enables privilege escalation from low-privileged access over the network.