#VU99287 Missing authentication for critical function in FortiManager - CVE-2024-47575

 

#VU99287 Missing authentication for critical function in FortiManager - CVE-2024-47575

Published: October 23, 2024 / Updated: January 10, 2025


Vulnerability identifier: #VU99287
Vulnerability risk: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: CVE-2024-47575
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
FortiManager
Software vendor:
Fortinet, Inc

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to missing authentication in FortiManager fgfmd daemon. A remote non-authenticated attacker can send specially crafted requests to the system and execute arbitrary commands, resulting in full system compromise.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install updates from vendor's website.

External links