ID:11049 - Exploit for Missing authentication for critical function in FortiManager - CVE-2024-47575

 
Main Vulnerability Database Exploits ID:11049 - Exploit for Missing authentication for critical function in FortiManager - CVE-2024-47575

ID:11049 - Exploit for Missing authentication for critical function in FortiManager - CVE-2024-47575

Published: January 10, 2025


Vulnerability identifier: #VU99287
Vulnerability risk: Critical
CVE-ID: CVE-2024-47575
CWE-ID: CWE-306
Exploitation vector: Remote access
Vulnerable software:
FortiManager

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to missing authentication in FortiManager fgfmd daemon. A remote non-authenticated attacker can send specially crafted requests to the system and execute arbitrary commands, resulting in full system compromise.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install updates from vendor's website.