---
id: CVE-2024-33503
title: >-
  A improper privilege management vulnerability in Fortinet FortiManager Cloud
  7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager
  Cloud 7.0 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0
  through 7…
summary: >-
  A improper privilege management vulnerability in Fortinet FortiManager Cloud
  7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager
  Cloud 7.0 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0
  through 7…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-266
vendor: fortinet
product: fortianalyzer
affected:
  - 'fortianalyzer >= 6.4.0, < 7.2.6'
  - 'fortianalyzer >= 7.4.0, < 7.4.4'
  - 'fortianalyzer_cloud >= 6.4.1, < 7.2.7'
  - 'fortianalyzer_cloud >= 7.4.1, < 7.4.3'
  - 'fortimanager >= 6.4.0, < 7.2.6'
  - 'fortimanager >= 7.4.0, < 7.4.4'
  - 'fortimanager_cloud >= 7.0.1, < 7.2.7'
  - 'fortimanager_cloud >= 7.4.1, < 7.4.4'
patched:
  - fortianalyzer 7.4.4
  - fortianalyzer_cloud 7.4.3
  - fortimanager 7.4.4
  - fortimanager_cloud 7.4.4
published: '2025-01-14'
updated: '2026-07-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-33503'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-24-127'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.00217
epssPercentile: 0.1241
ingestedAt: '2026-07-08T14:51:15.598Z'
---

## Overview

A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalation of privilege via specific shell commands

## Affected

- `fortianalyzer >= 6.4.0, < 7.2.6`
- `fortianalyzer >= 7.4.0, < 7.4.4`
- `fortianalyzer_cloud >= 6.4.1, < 7.2.7`
- `fortianalyzer_cloud >= 7.4.1, < 7.4.3`
- `fortimanager >= 6.4.0, < 7.2.6`
- `fortimanager >= 7.4.0, < 7.4.4`
- `fortimanager_cloud >= 7.0.1, < 7.2.7`
- `fortimanager_cloud >= 7.4.1, < 7.4.4`

## Remediation

Upgrade past the affected range:

- `fortianalyzer 7.4.4`
- `fortianalyzer_cloud 7.4.3`
- `fortimanager 7.4.4`
- `fortimanager_cloud 7.4.4`
