Missing authorization in FortiManager - CVE-2024-54020

 

Missing authorization in FortiManager - CVE-2024-54020

Published: May 13, 2025


Vulnerability identifier: #VU109034
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-54020
CWE-ID: CWE-862
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to manipulate data.

The vulnerability exists due to missing authorization of global threat feeds. An authenticated attacker can overwrite global threat feeds via crafted update requests.


Affected software

FortiManager

How to mitigate CVE-2024-54020

Install update from vendor's website.

FortiManager - addressed in versions 7.0.8, 7.2.2

External References

Related Security Bulletins