An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook
History

Tue, 14 Jan 2025 14:15:00 +0000

Type Values Removed Values Added
Description An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook
First Time appeared Fortinet
Fortinet fortisoar
Weaknesses CWE-78
CPEs cpe:2.3:a:fortinet:fortisoar:7.5.0:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortisoar
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2025-01-14T14:09:50.944Z

Updated: 2025-01-14T14:09:50.944Z

Reserved: 2024-10-09T09:03:09.962Z

Link: CVE-2024-48890

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-01-14T14:15:33.187

Modified: 2025-01-14T14:15:33.187

Link: CVE-2024-48890

cve-icon Redhat

No data.