CVE-2024-56497 Information

Description

An improper neutralization of special elements used in an os command (‘os command injection’) in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7 FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or commands via the CLI.

Reference

https://fortiguard.fortinet.com/psirt/FG-IR-23-170

Share on: