A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3 allows attacker to execute unauthorized code or commands via a brute-force attack.
The authentication mechanism in vulnerable versions of Fortinet products is insufficiently secured, enabling an effective brute-force attack on login credentials. An attacker, operating remotely over the network (AV:N), without the need to possess any privileges (PR:N) or user interaction (UI:N), can repeatedly attempt various authentication combinations. After successfully breaking through the security, they gain the ability to execute unauthorized code or commands on the vulnerable system. The vector indicates a high level of attack complexity (AC:H) and scope extending beyond the attacked system (S:C).
An attacker can execute arbitrary code or commands on a vulnerable device, gaining full control over the network management system. This results in potential loss of confidentiality, integrity, and availability of managed infrastructure (C:H/I:H/A:H).
Apply patches available from the manufacturer according to references (https://fortiguard.fortinet.com/psirt/FG-IR-24-221). Additionally, it is recommended to implement a policy of blocking accounts after a specified number of failed login attempts and restrict access to management interfaces exclusively to trusted IP addresses through appropriate firewall rules.
Fortinet FortiOS 7.4.0–7.4.4, 7.2.0–7.2.8, 7.0.0–7.0.15, 6.4.0–6.4.15; FortiProxy 7.4.0–7.4.4, 7.2.0–7.2.10, 7.0.0–7.0.17, 2.0.0–2.0.14; FortiManager 7.6.0–7.6.1, 7.4.1–7.4.3; FortiManager Cloud 7.4.1–7.4.3; FortiAnalyzer Cloud 7.4.1–7.4.3
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HFortinet Fortianalyzer
APPFortinet7.4.1 – 7.4.4 (excl.)7.6.0 – 7.6.2 (excl.)Fortinet Fortianalyzer Cloud
APPFortinet7.4.1 – 7.4.4 (excl.)Fortinet Fortimanager
APPFortinet7.4.1 – 7.4.4 (excl.)7.6.0 – 7.6.2 (excl.)Fortinet Fortimanager Cloud
APPFortinet7.4.1 – 7.4.4 (excl.)Fortinet FortiOS
OSFortinet7.4.0 – 7.4.5 (excl.)6.4.0 – 7.0.16 (excl.)7.2.0 – 7.2.9 (excl.)Fortinet Fortiproxy
APPFortinet7.4.0 – 7.4.5 (excl.)2.0.0 – 2.0.15 (excl.)7.0.0 – 7.0.18 (excl.)7.2.0 – 7.2.11 (excl.)
Related vulnerabilities
Fortinet – Auth Bypass przez FortiCloud SSO w wielu produktach
Fortinet FortiOS/FortiProxy/FortiSwitchManager — Auth Bypass przez SAML
Authentication Bypass w FortiOS i FortiProxy — przejęcie uprawnień super-admin
Brak uwierzytelnienia krytycznej funkcji w Fortinet FortiManager — RCE
Krytyczna podatność format string RCE w Fortinet FortiOS, FortiProxy i FortiSwitchManager