VYPR
Unrated severityNVD Advisory· Published Nov 12, 2024· Updated Nov 13, 2024

CVE-2024-33510

CVE-2024-33510

Description

An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below; FortiSASE version 24.2.b SSL-VPN web user interface may allow a remote unauthenticated attacker to perform phishing attempts via crafted requests.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Fortinet/Fortiosv52 versions
    cpe:2.3:o:fortinet:fortios:7.4.3:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fortinet:fortios:7.4.3:*:*:*:*:*:*:*range: 7.4.0
    • (no CPE)range: <= 7.4.3, <= 7.2.8, <= 7.0.16
  • Fortinet/Fortiproxyllm-fuzzy2 versions
    <= 7.4.3, <= 7.2.9, <= 7.0.16+ 1 more
    • (no CPE)range: <= 7.4.3, <= 7.2.9, <= 7.0.16
    • (no CPE)range: 7.4.0
  • Range: = 24.2.b

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.

CVE-2024-33510 · VYPR