CVE-2024-47575
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.
- Affected products
- Fortigate, Fortimanager, Fortimanager Cloud
- Fortinet Fortimanager
- < 6.2.13, 6.4.15, 7.0.13, 7.2.8, 7.4.5, 7.6.0
- Fortinet Fortimanager Cloud
- ≤ 6.4.7, 7.0.13, 7.2.8, 7.4.5
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 95.0% (100th percentile)
- Weakness
- CWE-306
- NVD status
- Analyzed
- Published
- 2024-10-23
Fix
Please upgrade to FortiManager Cloud version 7.6.2 or above Please upgrade to FortiManager Cloud version 7.4.5 or above Please upgrade to FortiManager Cloud version 7.2.8 or above Please upgrade to FortiManager Cloud version 7.0.13 or above Please upgrade to FortiManager version 7.6.1 or above Please upgrade to FortiManager version 7.4.5 or above Please upgrade to FortiManager version 7.2.8 or above Please upgrade to FortiManager version 7.0.13 or above Please upgrade to FortiManager version 6.4.15 or above Please upgrade to FortiManager version 6.2.13 or above
6 known exploits for CVE-2024-47575
Proof-of-concept code and exploit modules indexed by Sploitus