#VU99287 Missing authentication for critical function in FortiManager - CVE-2024-47575
Published: October 23, 2024 / Updated: January 10, 2025
FortiManager
Fortinet, Inc
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authentication in FortiManager fgfmd daemon. A remote non-authenticated attacker can send specially crafted requests to the system and execute arbitrary commands, resulting in full system compromise.
Note, the vulnerability is being actively exploited in the wild.