A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.
The attacker sends specially crafted network requests to the vulnerable FortiManager system without needing any authentication credentials. A critical system function is accessible without identity verification, which is a missing authentication vulnerability (CWE-306). This allows arbitrary code or system commands to be executed on the management server.
An unauthenticated remote attacker can gain full control over the FortiManager system by executing arbitrary code or system commands, which may lead to compromise of managed network infrastructure, theft of configuration data, and lateral movement within the network.
Security patches available from the vendor must be applied immediately according to references published by Fortinet (FG-IR-24-423 on fortiguard.fortinet.com). Until the patch is deployed, it is recommended to restrict network access to the FortiManager management interface to trusted IP addresses only and to monitor the system for suspicious activity.
FortiManager 7.6.0; FortiManager 7.4.0–7.4.4; FortiManager 7.2.0–7.2.7; FortiManager 7.0.0–7.0.12; FortiManager 6.4.0–6.4.14; FortiManager 6.2.0–6.2.12; FortiManager Cloud 7.4.1–7.4.4; FortiManager Cloud 7.2.1–7.2.7; FortiManager Cloud 7.0.1–7.0.12; FortiManager Cloud 6.4.1–6.4.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HFortinet Fortimanager
APPFortinet7.6.06.4.0 – 6.4.15 (excl.)7.0.0 – 7.0.13 (excl.)7.2.0 – 7.2.8 (excl.)7.4.0 – 7.4.5 (excl.)6.2.0 – 6.2.13 (excl.)Fortinet Fortimanager Cloud
APPFortinet6.4.1 – 6.4.77.0.1 – 7.0.13 (excl.)7.2.1 – 7.2.8 (excl.)7.4.1 – 7.4.5 (excl.)
CISA KEV — detailsi
- Vendori
- Fortinet ↗
- Producti
- FortiManager
- Added to KEVi
- October 23, 2024
- Remediation deadline (US Federal)i
- November 13, 2024(overdue)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
Related vulnerabilities
Fortinet – Auth Bypass przez FortiCloud SSO w wielu produktach
Buffer Underflow w interfejsie administracyjnym Fortinet FortiOS / FortiProxy — RCE bez uwierzytelnienia
Słabe uwierzytelnienie w Fortinet FortiOS/FortiProxy/FortiManager umożliwia RCE
Krytyczna podatność w WebUI FortiManager — strona backup FTP
Brak weryfikacji integralności systemu plików w Fortinet FortiManager VM