First published: Thu Oct 17 2024(Updated: )
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.
Credit: psirt@fortinet.com psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiManager | ||
Fortinet FortiManager | >=6.2.0<6.2.13 | |
Fortinet FortiManager | >=6.4.0<6.4.15 | |
Fortinet FortiManager | >=7.0.0<7.0.13 | |
Fortinet FortiManager | >=7.2.0<7.2.8 | |
Fortinet FortiManager | >=7.4.0<7.4.5 | |
Fortinet FortiManager | =7.6.0 | |
Fortinet FortiManager Cloud | >=6.4.1<=6.4.7 | |
Fortinet FortiManager Cloud | >=7.0.1<7.0.13 | |
Fortinet FortiManager Cloud | >=7.2.1<7.2.8 | |
Fortinet FortiManager Cloud | >=7.4.1<7.4.5 | |
Fortinet FortiManager | =. | |
Fortinet FortiManager | >=7.4.0<=7.4.4 | |
Fortinet FortiManager | >=7.2.0<=7.2.7 | |
Fortinet FortiManager | >=7.0.0<=7.0.12 | |
Fortinet FortiManager | >=6.4.0<=6.4.14 | |
Fortinet FortiManager | >=6.2.0<=6.2.12 | |
Fortinet FortiManager Cloud | >=7.4.1<=7.4.4 | |
Fortinet FortiManager Cloud | >=7.2.1<=7.2.7 | |
Fortinet FortiManager Cloud | >=7.0.1<=7.0.12 | |
Fortinet FortiManager Cloud | >=6.4 |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Please upgrade to FortiManager Cloud version 7.6.2 or above Please upgrade to FortiManager Cloud version 7.4.5 or above Please upgrade to FortiManager Cloud version 7.2.8 or above Please upgrade to FortiManager Cloud version 7.0.13 or above Please upgrade to FortiManager version 7.6.1 or above Please upgrade to FortiManager version 7.4.5 or above Please upgrade to FortiManager version 7.2.8 or above Please upgrade to FortiManager version 7.0.13 or above Please upgrade to FortiManager version 6.4.15 or above Please upgrade to FortiManager version 6.2.13 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47575 is classified as a critical vulnerability due to missing authentication for critical functions in FortiManager.
To remediate CVE-2024-47575, upgrade FortiManager to version 7.6.1 or apply a patch corresponding to your version.
CVE-2024-47575 affects multiple versions of FortiManager, specifically versions 6.2.0 to 6.2.12, 6.4.0 to 6.4.14, 7.0.0 to 7.0.12, 7.2.0 to 7.2.7, 7.4.0 to 7.4.4, and 7.6.0.
The vulnerability CVE-2024-47575 impacts Fortinet FortiManager and FortiManager Cloud products across various versions.
There is no official workaround for CVE-2024-47575, and the recommended action is to immediately upgrade to a patched version.