{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-21760","assignerOrgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","state":"PUBLISHED","assignerShortName":"fortinet","dateReserved":"2024-01-02T10:15:00.527Z","datePublished":"2025-03-18T13:56:44.525Z","dateUpdated":"2025-03-18T14:15:03.959Z"},"containers":{"cna":{"affected":[{"vendor":"Fortinet","product":"FortiSOAR","cpes":["cpe:2.3:a:fortinet:fortisoar:7.4.5:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.4.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.4.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.4.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.4.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.3.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.3.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.3.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.3.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.2.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.2.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.0.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.0.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.0.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:7.0.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:6.4.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:6.4.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:6.4.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortisoar:6.4.0:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","versions":[{"versionType":"semver","version":"7.4.0","lessThanOrEqual":"7.4.5","status":"affected"},{"versionType":"semver","version":"7.3.0","lessThanOrEqual":"7.3.3","status":"affected"},{"versionType":"semver","version":"7.2.0","lessThanOrEqual":"7.2.2","status":"affected"},{"versionType":"semver","version":"7.0.0","lessThanOrEqual":"7.0.3","status":"affected"},{"versionType":"semver","version":"6.4.3","lessThanOrEqual":"6.4.4","status":"affected"},{"versionType":"semver","version":"6.4.0","lessThanOrEqual":"6.4.1","status":"affected"}]}],"descriptions":[{"lang":"en","value":"An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker to execute arbitrary code on the host via a playbook code snippet."}],"providerMetadata":{"orgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","shortName":"fortinet","dateUpdated":"2025-03-18T13:56:44.525Z"},"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-94","description":"Execute unauthorized code or commands","type":"CWE"}]}],"metrics":[{"format":"CVSS","cvssV3_1":{"version":"3.1","attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H/E:U/RL:X/RC:X"}}],"solutions":[{"lang":"en","value":"Please upgrade to FortiSOAR version 7.5.0 or above"}],"references":[{"name":"https://fortiguard.fortinet.com/psirt/FG-IR-23-420","url":"https://fortiguard.fortinet.com/psirt/FG-IR-23-420"}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-03-18T14:14:53.853979Z","id":"CVE-2024-21760","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-03-18T14:15:03.959Z"}}]}}