CVE-2024-23670: High severity Fortinet FortiWebManager vulnerability
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiWebManagerto a version that resolves this vulnerability.Fixed in 6.2.5 - Upgrade
Upgrade
Fortinet FortiWebManagerto a version that resolves this vulnerability.Fixed in 6.3.1 - Upgrade
Upgrade
Fortinet FortiWebManagerto a version that resolves this vulnerability.Fixed in 7.0.5 - Upgrade
Upgrade
Fortinet FortiWebManagerto a version that resolves this vulnerability.Fixed in 7.2.1 - Upgrade
Upgrade
Fortinet FortiWebManagerto a version that resolves this vulnerability.Fixed in 7.4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23670?
CVE-2024-23670 has been classified as a high-severity vulnerability due to its potential for unauthorized code execution.
How do I fix CVE-2024-23670?
To fix CVE-2024-23670, upgrade Fortinet FortiWebManager to a version that is not affected, such as those later than 7.0.5, 6.2.5, or 6.0.2.
Which versions of Fortinet FortiWebManager are affected by CVE-2024-23670?
CVE-2024-23670 affects Fortinet FortiWebManager versions 6.0.2, 6.2.3 through 6.2.4, 7.0.0 through 7.0.4, and 7.2.0.
What can an attacker do with CVE-2024-23670?
An attacker can execute unauthorized code or commands via HTTP requests or the CLI due to improper authorization in CVE-2024-23670.
Is CVE-2024-23670 related to any specific Fortinet product?
Yes, CVE-2024-23670 specifically affects Fortinet FortiWebManager.