CVE-2024-23669: Input Validation
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiWebManagerto a version that resolves this vulnerability.Fixed in 6.2.5 - Upgrade
Upgrade
Fortinet FortiWebManagerto a version that resolves this vulnerability.Fixed in 6.3.1 - Upgrade
Upgrade
Fortinet FortiWebManagerto a version that resolves this vulnerability.Fixed in 7.0.5 - Upgrade
Upgrade
Fortinet FortiWebManagerto a version that resolves this vulnerability.Fixed in 7.2.1 - Upgrade
Upgrade
Fortinet FortiWebManagerto a version that resolves this vulnerability.Fixed in 7.4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23669?
CVE-2024-23669 has been classified as critical due to its potential to allow unauthorized code execution.
How do I fix CVE-2024-23669?
To fix CVE-2024-23669, users should upgrade to the latest version of Fortinet FortiWebManager that is not affected by this vulnerability.
Which versions of Fortinet FortiWebManager are affected by CVE-2024-23669?
CVE-2024-23669 affects Fortinet FortiWebManager versions 7.0.0 through 7.0.4, 6.2.3 through 6.2.4, 6.3.0, and 6.0.2.
What types of attacks are possible due to CVE-2024-23669?
Attackers can exploit CVE-2024-23669 to execute unauthorized commands via HTTP requests or command line interface.
Is there a workaround for CVE-2024-23669?
There are no specific workarounds documented for CVE-2024-23669; the recommended action is to apply the security updates.