SB2025051336 - Missing authorization in FortiManager
Published: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing authorization (CVE-ID: CVE-2024-54020)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local privileged user to manipulate data.
The vulnerability exists due to missing authorization of global threat feeds. An authenticated attacker can overwrite global threat feeds via crafted update requests.
Remediation
Install update from vendor's website.