{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-56497","assignerOrgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","state":"PUBLISHED","assignerShortName":"fortinet","dateReserved":"2024-12-26T15:39:07.871Z","datePublished":"2025-01-14T14:09:27.433Z","dateUpdated":"2025-01-14T20:55:21.625Z"},"containers":{"cna":{"affected":[{"vendor":"Fortinet","product":"FortiMail","cpes":["cpe:2.3:a:fortinet:fortimail:7.2.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:7.2.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:7.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:7.2.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:7.2.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:7.0.6:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:7.0.5:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:7.0.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:7.0.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:7.0.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:7.0.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:7.0.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:6.4.7:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:6.4.6:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:6.4.5:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:6.4.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:6.4.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:6.4.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:6.4.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimail:6.4.0:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","versions":[{"versionType":"semver","version":"7.2.0","lessThanOrEqual":"7.2.4","status":"affected"},{"versionType":"semver","version":"7.0.0","lessThanOrEqual":"7.0.6","status":"affected"},{"versionType":"semver","version":"6.4.0","lessThanOrEqual":"6.4.7","status":"affected"}]},{"vendor":"Fortinet","product":"FortiRecorder","cpes":["cpe:2.3:a:fortinet:fortirecorder:7.0.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortirecorder:6.4.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortirecorder:6.4.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortirecorder:6.4.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortirecorder:6.4.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortirecorder:6.4.0:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","versions":[{"version":"7.0.0","status":"affected"},{"versionType":"semver","version":"6.4.0","lessThanOrEqual":"6.4.4","status":"affected"}]}],"descriptions":[{"lang":"en","value":"An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or commands via the CLI."}],"providerMetadata":{"orgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","shortName":"fortinet","dateUpdated":"2025-01-14T14:09:27.433Z"},"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-78","description":"Execute unauthorized code or commands","type":"CWE"}]}],"metrics":[{"format":"CVSS","cvssV3_1":{"version":"3.1","attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:X"}}],"solutions":[{"lang":"en","value":"Please upgrade to FortiMail version 7.4.0 or above \nPlease upgrade to FortiMail version 7.2.5 or above \nPlease upgrade to FortiMail version 7.0.7 or above \nPlease upgrade to FortiMail version 6.4.8 or above \nPlease upgrade to FortiRecorder version 7.2.0 or above \nPlease upgrade to FortiRecorder version 7.0.2 or above \nPlease upgrade to FortiRecorder version 6.4.5 or above"}],"references":[{"name":"https://fortiguard.fortinet.com/psirt/FG-IR-23-170","url":"https://fortiguard.fortinet.com/psirt/FG-IR-23-170"}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-01-14T15:16:38.876441Z","id":"CVE-2024-56497","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-01-14T20:55:21.625Z"}}]}}