CVE-2024-47575
Description
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.
Summary dbcve.org
A missing authentication check in FortiManager's critical functions allows unauthenticated remote attackers to execute arbitrary code or commands via specially crafted HTTP requests. This is a pre-authentication command injection vulnerability affecting FortiManager versions 6.2, 6.4, 7.0, 7.2, 7.4, and 7.6 (and corresponding Cloud versions), enabling complete system compromise without credentials.
Mitigation
Apply Fortinet's available patches for this vulnerability immediately. If patches cannot be applied, restrict network access to FortiManager management interfaces using firewall rules or VPNs to limit exposure to trusted networks only.