CVE-2024-35277: Missing authentication for managed device configuration files
A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the managed devices by sending specifically crafted packets
Other sources
A missing authentication for critical function vulnerability [CWE-306] in FortiManager and FortiPortal may allow a remote unauthenticated attacker to extract the configuration of all managed devices
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35277?
CVE-2024-35277 has a high severity due to missing authentication for critical functions, allowing unauthorized access to device configurations.
How do I fix CVE-2024-35277?
To fix CVE-2024-35277, upgrade to FortiManager version 7.4.3 or later, 7.2.7 or later, 7.0.13 or later, or ensure FortiPortal is updated to versions above 6.0.15.
Which versions are affected by CVE-2024-35277?
CVE-2024-35277 affects Fortinet FortiPortal versions 6.0.0 to 6.0.15 and FortiManager versions 7.4.0 to 7.4.2, 7.2.0 to 7.2.5, 7.0.0 to 7.0.12, and 6.4.0 to 6.4.14.
What are the implications of CVE-2024-35277 on security?
The implications of CVE-2024-35277 on security include the potential for attackers to access and manipulate device configurations leading to further breaches.
Is there a mitigation for CVE-2024-35277?
While upgrading is the main remedy, ensuring proper access controls and monitoring can help mitigate the risks posed by CVE-2024-35277.