FG-IR-24-032: FortiOS - Improper authentication in fgfmd
An improper authentication vulnerability [CWE-287] in FortiManager, FortiOS, FortiPAM, FortiPortal, FortiProxy and FortiSwitchManager fgfmd daemon may allow an unauthenticated attacker to inject (but not receive) packets in tunnels established between a FortiManager and the targeted device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-032?
The severity of FG-IR-24-032 is classified as improper authentication vulnerability.
How do I fix FG-IR-24-032?
To fix FG-IR-24-032, update FortiManager, FortiOS, FortiPAM, FortiPortal, FortiProxy, or FortiSwitchManager to the respective remedial versions listed in the advisory.
What products are affected by FG-IR-24-032?
The affected products by FG-IR-24-032 include FortiManager, FortiOS, FortiPAM, FortiPortal, FortiProxy, and FortiSwitchManager.
Is FG-IR-24-032 an authentication vulnerability?
Yes, FG-IR-24-032 is an improper authentication vulnerability that allows unauthenticated attackers to inject packets.
Which versions of FortiManager are vulnerable according to FG-IR-24-032?
Versions of FortiManager between 7.4.0 and 7.4.2, 7.2.0 and 7.2.4, 7.0.0 and 7.0.11, and 6.4.0 and 6.4.14 are vulnerable to FG-IR-24-032.