An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-415 |     | 
History
                    Mon, 03 Feb 2025 22:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Fortinet fortisoar Imap Connector | |
| CPEs | cpe:2.3:a:fortinet:fortisoar_imap_connector:*:*:*:*:*:*:*:* | |
| Vendors & Products | Fortinet fortisoar Imap Connector | 
Wed, 15 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 14 Jan 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook | |
| First Time appeared | Fortinet Fortinet fortisoar | |
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:fortinet:fortisoar:7.5.0:*:*:*:*:*:*:* | |
| Vendors & Products | Fortinet Fortinet fortisoar | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: fortinet
Published: 2025-01-14T14:09:50.944Z
Updated: 2025-01-15T14:55:00.652Z
Reserved: 2024-10-09T09:03:09.962Z
Link: CVE-2024-48890
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-01-15T14:54:55.894Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-01-14T14:15:33.187
Modified: 2025-02-03T22:13:42.850
Link: CVE-2024-48890
 Redhat
                        Redhat
                    No data.