CRITICAL

CVE-2024-47575

Fortinet Fortimanager 2024-10-23 CVSS v3.1
CVSS
9.8
KEV

Description

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.

Summary dbcve.org

A missing authentication check in FortiManager's critical functions allows unauthenticated remote attackers to execute arbitrary code or commands via specially crafted HTTP requests. This is a pre-authentication command injection vulnerability affecting FortiManager versions 6.2, 6.4, 7.0, 7.2, 7.4, and 7.6 (and corresponding Cloud versions), enabling complete system compromise without credentials.

Mitigation

Apply Fortinet's available patches for this vulnerability immediately. If patches cannot be applied, restrict network access to FortiManager management interfaces using firewall rules or VPNs to limit exposure to trusted networks only.

Proof of Concept

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

95.07%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE