216.73.217.22

CVE-2024-21760

· Published 18/03/2025 14:15 · Modified 18/03/2025 14:15

Labels: CVE-2024-21760 2025-03-18CVE-2024-21760CWE-94[email protected]

Essential information

Published
18/03/2025 14:15
Modified
18/03/2025 14:15
Author
Creator
CVSS
8.4 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

CVSS metrics

Description

An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker to execute arbitrary code on the host via a playbook code snippet.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
fortinet / fortisoar cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:*

References