CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2024-47575

CVSS 9.8v3.1pub. 2024-10-23upd. 2025-10-24

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.

🤖 AI Analysis
How it works

The attacker sends specially crafted network requests to the vulnerable FortiManager system without needing any authentication credentials. A critical system function is accessible without identity verification, which is a missing authentication vulnerability (CWE-306). This allows arbitrary code or system commands to be executed on the management server.

Impact

An unauthenticated remote attacker can gain full control over the FortiManager system by executing arbitrary code or system commands, which may lead to compromise of managed network infrastructure, theft of configuration data, and lateral movement within the network.

Mitigation & patch

Security patches available from the vendor must be applied immediately according to references published by Fortinet (FG-IR-24-423 on fortiguard.fortinet.com). Until the patch is deployed, it is recommended to restrict network access to the FortiManager management interface to trusted IP addresses only and to monitor the system for suspicious activity.

Who is affected

FortiManager 7.6.0; FortiManager 7.4.0–7.4.4; FortiManager 7.2.0–7.2.7; FortiManager 7.0.0–7.0.12; FortiManager 6.4.0–6.4.14; FortiManager 6.2.0–6.2.12; FortiManager Cloud 7.4.1–7.4.4; FortiManager Cloud 7.2.1–7.2.7; FortiManager Cloud 7.0.1–7.0.12; FortiManager Cloud 6.4.1–6.4.7

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Fortinet Fortimanager

    APP
    Fortinet
    7.6.06.4.0 – 6.4.15 (excl.)7.0.0 – 7.0.13 (excl.)7.2.0 – 7.2.8 (excl.)7.4.0 – 7.4.5 (excl.)6.2.0 – 6.2.13 (excl.)
  • Fortinet Fortimanager Cloud

    APP
    Fortinet
    6.4.1 – 6.4.77.0.1 – 7.0.13 (excl.)7.2.1 – 7.2.8 (excl.)7.4.1 – 7.4.5 (excl.)

CISA KEV — detailsi

Vendori
Fortinet
Producti
FortiManager
Added to KEVi
October 23, 2024
Remediation deadline (US Federal)i
November 13, 2024(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 13 listopada 2024
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-24858CRITICAL9.8⚠ KEVPL ✓same product

Fortinet – Auth Bypass przez FortiCloud SSO w wielu produktach

CVE-2023-25610CRITICAL9.8PL ✓same product

Buffer Underflow w interfejsie administracyjnym Fortinet FortiOS / FortiProxy — RCE bez uwierzytelnienia

CVE-2024-48886CRITICAL9.0PL ✓same product

Słabe uwierzytelnienie w Fortinet FortiOS/FortiProxy/FortiManager umożliwia RCE

CVE-2015-3613CRITICAL9.8PL ✓same product

Krytyczna podatność w WebUI FortiManager — strona backup FTP

CVE-2019-6695CRITICAL9.8PL ✓same product

Brak weryfikacji integralności systemu plików w Fortinet FortiManager VM