CVE-2024-33508: Fortinet FortiClient Enterprise Management Server

High severity, CVSS 7.3. EPSS: 1.3% chance of exploitation in the next 30 days.

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.

Affected products

  • Fortinet FortiClient Enterprise Management Server: from 7.0.0, before 7.0.13 (fixed in 7.0.13); from 7.2.0, before 7.2.5 (fixed in 7.2.5)

Published 2024-09-10. Last modified 2026-06-17.