CVE-2024-36505: Real-time file system integrity checking write protection bypass
An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system.
Other sources
An improper access control vulnerability [CWE-284] in FortiOS may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36505?
CVE-2024-36505 is classified as a high severity vulnerability due to improper access control.
How do I fix CVE-2024-36505?
To mitigate CVE-2024-36505, upgrade to FortiOS versions 7.4.4 or higher, 7.2.8 or higher, or 7.0.15 or higher.
Who is affected by CVE-2024-36505?
CVE-2024-36505 affects users of FortiOS versions 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14, and certain 6.4.x versions.
What type of vulnerability is CVE-2024-36505?
CVE-2024-36505 is an improper access control vulnerability categorized under CWE-284.
Can CVE-2024-36505 be exploited remotely?
Yes, CVE-2024-36505 can potentially be exploited by an attacker who has already obtained write access to the underlying system.