## https://sploitus.com/exploit?id=334BE2DE-EBFB-5667-9548-6E39A519148C
CVE-2024-47575 is a serious vulnerability in Fortinet’s FortiManager and FortiManager Cloud products. It stems from a lack of authentication for critical functions in the fgfmsd daemon process. This vulnerability allows unauthorized remote attackers to execute arbitrary code or commands on affected systems via specially crafted requests. Specifically, fgfmsd handles communication between FortiManager and FortiGate devices. Due to the absence of proper authentication mechanisms, attackers can exploit this vulnerability by sending specially crafted requests to fgfmsd, bypassing security controls and executing arbitrary commands or code, thereby potentially gaining full control over the affected system. The severity of this vulnerability lies in the fact that attackers can exploit it remotely without requiring any credentials, which may lead to the exposure of sensitive information or complete control over the system. Therefore, it is recommended that affected users update to the fixed version as soon as possible or take the mitigation measures provided by the vendor.