CVE-2024-33505: Fortinet Fortianalyzer
High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specially crafted http requests
Affected products
- Fortinet Fortianalyzer: from 6.4.0, before 7.2.6 (fixed in 7.2.6); from 7.4.0, before 7.4.3 (fixed in 7.4.3)
- Fortinet FortiManager: from 6.0.0, before 7.2.7 (fixed in 7.2.7); from 7.4.0, before 7.4.3 (fixed in 7.4.3)
- Fortinet FortiManager Cloud: from 6.4.1, before 7.2.7 (fixed in 7.2.7); from 7.4.1, before 7.4.3 (fixed in 7.4.3)
Published 2024-11-12. Last modified 2026-06-17.