peter bassill · operator
$ cve CVE-2024-47575 JSON

CVE-2024-47575 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 94.8% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2024-11-13.

Description

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS94.77% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-306
On CISA KEVyes — remediate by 2024-11-13
Public exploitnone known
Published2024-10-23
Last modified2026-06-17

CISA KEV

NameFortinet FortiManager Missing Authentication Vulnerability
Added2024-10-23
Due2024-11-13
Vendor / productFortinet / FortiManager
Ransomware usenone reported

Affected (2)

VendorProduct
fortinetfortimanager
fortinetfortimanager cloud

References

→ the Explorer  ·  watch your stack  ·  NVD