CVE-2024-21759: Medium severity fortinet fortiportal vulnerability
Published Jul 9, 2024
·Updated
An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests.
Affected Software
2 affected components
Fortinet FortiPortal>=7.0.0<7.0.7
Fortinet FortiPortal=7.2.0
Remediation
Information
Please upgrade to FortiPortal version 7.4.0 or above
Please upgrade to FortiPortal version 7.2.3 or above
Please upgrade to FortiPortal version 7.0.8 or above
Event History
Jul 9, 2024
CVE Published
via MITRE·03:33 PM
Data Sourced
via MITRE·03:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-21759?
CVE-2024-21759 is classified as a critical vulnerability due to its potential for unauthorized access to sensitive resources.
2
How do I fix CVE-2024-21759?
To fix CVE-2024-21759, upgrade Fortinet FortiPortal to version 7.0.7 or later, or to a patched version beyond 7.2.0.
3
What systems are affected by CVE-2024-21759?
CVE-2024-21759 affects Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0.
4
What type of vulnerability is CVE-2024-21759?
CVE-2024-21759 is an authorization bypass vulnerability that allows attackers to view unauthorized resources.
5
Can CVE-2024-21759 be exploited over the internet?
Yes, CVE-2024-21759 can be exploited through HTTP or HTTPS requests.