CVE-2024-33505: Fortinet Fortianalyzer

High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.

A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specially crafted http requests

Affected products

  • Fortinet Fortianalyzer: from 6.4.0, before 7.2.6 (fixed in 7.2.6); from 7.4.0, before 7.4.3 (fixed in 7.4.3)
  • Fortinet FortiManager: from 6.0.0, before 7.2.7 (fixed in 7.2.7); from 7.4.0, before 7.4.3 (fixed in 7.4.3)
  • Fortinet FortiManager Cloud: from 6.4.1, before 7.2.7 (fixed in 7.2.7); from 7.4.1, before 7.4.3 (fixed in 7.4.3)

Published 2024-11-12. Last modified 2026-06-17.