CVE-2024-48887: Unverified password change via set_password endpoint
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request
Other sources
An unverified password change vulnerability [CWE-620] in FortiSwitch GUI may allow a remote unauthenticated attacker to modify admin passwords via a specially crafted request.
— FortiGuard
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-48887?
CVE-2024-48887 has been classified as a high-severity vulnerability due to its potential to allow unauthorized password changes by remote attackers.
How do I fix CVE-2024-48887?
To mitigate CVE-2024-48887, you should upgrade your FortiSwitch to the latest version that is not affected by this vulnerability.
Which versions of FortiSwitch are affected by CVE-2024-48887?
FortiSwitch versions prior to 7.6.1 and those in the ranges 7.4.0 to 7.4.4, 7.2.0 to 7.2.8, 7.0.0 to 7.0.10, and 6.4.0 to 6.4.14 are affected by CVE-2024-48887.
Can CVE-2024-48887 be exploited remotely?
Yes, CVE-2024-48887 can be exploited remotely by an unauthenticated attacker who sends a specially crafted request.
What type of vulnerability is CVE-2024-48887 classified as?
CVE-2024-48887 is classified as an unverified password change vulnerability (CWE-620) affecting the FortiSwitch GUI.