CVE-2024-47575
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| fortinet | fortimanager | >= 6.2.0, < 6.2.13 |
| fortinet | fortimanager | >= 6.4.0, < 6.4.15 |
| fortinet | fortimanager | >= 7.0.0, < 7.0.13 |
| fortinet | fortimanager | >= 7.2.0, < 7.2.8 |
| fortinet | fortimanager | >= 7.4.0, < 7.4.5 |
| fortinet | fortimanager | 7.6.0 |
| fortinet | fortimanager_cloud | >= 6.4.1, <= 6.4.7 |
| fortinet | fortimanager_cloud | >= 7.0.1, < 7.0.13 |
| fortinet | fortimanager_cloud | >= 7.2.1, < 7.2.8 |
| fortinet | fortimanager_cloud | >= 7.4.1, < 7.4.5 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-47575