CVE-2024-45324
HIGHDescription
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and before 1.3.1, FortiSRA version 1.4.0 through 1.4.2 and before 1.3.1 and FortiWeb version 7.4.0 through 7.4.5, version 7.2.0 through 7.2.10 and before 7.0.10 allows a privileged attacker to execute unauthorized code or commands via specially crafted HTTP or HTTPS commands.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| fortinet | fortios |
| fortinet | fortios |
| fortinet | fortios |
| fortinet | fortios |
| fortinet | fortios |
| fortinet | fortipam |
| fortinet | fortipam |
| fortinet | fortiproxy |
| fortinet | fortiproxy |
| fortinet | fortiproxy |
| fortinet | fortiproxy |
| fortinet | fortiweb |
| fortinet | fortiweb |
| fortinet | fortiweb |
| fortinet | fortiweb |
| fortinet | fortisra |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-45324? +
How severe is CVE-2024-45324? +
What products are affected by CVE-2024-45324? +
How do I check if I'm vulnerable to CVE-2024-45324? +
Related Vulnerabilities
ComSndFTP FTP Server version 1.3.7 Beta contains a format string vulnerability in its handling of the USER command. By sending …
Solar FTP Server fails to properly handle format strings passed to the USER command. When a specially crafted string containing …
WM Downloader version 3.1.2.2 is vulnerable to a buffer overflow when processing a specially crafted .m3u playlist file. The application …
In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan …
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass …
Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service …