Junglewise Threat Intelligence

CVE-2024-47575: Fortinet FortiManager Missing Authentication Vulnerability

CVE-2024-47575 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-10-23

Technologies: Fortinet FortiManager. Vendors: Fortinet.

Executive brief

A missing authentication vulnerability in the fgfmd daemon of Fortinet FortiManager and FortiManager Cloud allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. This vulnerability has been observed being exploited in the wild.

Affected products

  • Fortinet FortiManager 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.7, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.12
  • Fortinet FortiManager Cloud 7.4.1 through 7.4.4, 7.2.1 through 7.2.7, 7.0.1 through 7.0.12, 6.4.1 through 6.4.7

Timeline

  • 2024-10-23: disclosed
  • 2024-10-23: advisory
  • 2024-10-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-10-23: exploited: Reported as exploited in the wild at time of publication.

Related threats