CVE-2024-47575 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 94.8% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2024-11-13.
Description
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 94.77% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-306 |
| On CISA KEV | yes — remediate by 2024-11-13 |
| Public exploit | none known |
| Published | 2024-10-23 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Fortinet FortiManager Missing Authentication Vulnerability |
|---|---|
| Added | 2024-10-23 |
| Due | 2024-11-13 |
| Vendor / product | Fortinet / FortiManager |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| fortinet | fortimanager |
| fortinet | fortimanager cloud |
References
→ the Explorer · watch your stack · NVD