CVE-2024-48886: Critical severity fortios vulnerability
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3 allows attacker to execute unauthorized code or commands via a brute-force attack.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48886?
CVE-2024-48886 is rated as a critical vulnerability due to weak authentication in multiple Fortinet products.
How do I fix CVE-2024-48886?
To fix CVE-2024-48886, upgrade Fortinet FortiOS, FortiProxy, or FortiManager to the latest patched versions.
Which versions are affected by CVE-2024-48886?
CVE-2024-48886 affects Fortinet FortiOS versions 7.4.0 through 7.4.4, among others, as well as FortiProxy and FortiManager in specified versions.
What products are impacted by CVE-2024-48886?
The impacted products include Fortinet FortiOS, FortiProxy, FortiManager, FortiManager Cloud, and FortiAnalyzer Cloud.
Is user intervention required to mitigate CVE-2024-48886?
Yes, user intervention is required to mitigate CVE-2024-48886 by applying the recommended software updates.