CVE-2024-47575: Missing authentication in fgfmsd
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.
Other sources
A missing authentication for critical function vulnerability [CWE-306] in FortiManager fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
Reports have shown this vulnerability to be exploited in the wild.
— FortiGuard
Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 6.2.13 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 6.4.15 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.0.13 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.2.8 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.4.5 - Upgrade
Upgrade
FortiManagerto a version that resolves this vulnerability.Fixed in 7.6.1 - Upgrade
Upgrade
FortiManager Cloudto a version that resolves this vulnerability.Fixed in 6.4.1 - Upgrade
Upgrade
FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.0.13 - Upgrade
Upgrade
FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.2.8 - Upgrade
Upgrade
FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.4.5 - Upgrade
Upgrade
FortiManager Cloudto a version that resolves this vulnerability.Fixed in 7.6.2 - Compensating control
Discontinue use of the product if mitigations per vendor instructions are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-47575?
CVE-2024-47575 is classified as a critical vulnerability due to missing authentication for critical functions in FortiManager.
How do I fix CVE-2024-47575?
To remediate CVE-2024-47575, upgrade FortiManager to version 7.6.1 or apply a patch corresponding to your version.
Which versions are affected by CVE-2024-47575?
CVE-2024-47575 affects multiple versions of FortiManager, specifically versions 6.2.0 to 6.2.12, 6.4.0 to 6.4.14, 7.0.0 to 7.0.12, 7.2.0 to 7.2.7, 7.4.0 to 7.4.4, and 7.6.0.
What products are vulnerable to CVE-2024-47575?
The vulnerability CVE-2024-47575 impacts Fortinet FortiManager and FortiManager Cloud products across various versions.
Is there a workaround for CVE-2024-47575?
There is no official workaround for CVE-2024-47575, and the recommended action is to immediately upgrade to a patched version.