FG-IR-24-135: Missing authentication for managed device configuration files
A missing authentication for critical function vulnerability [CWE-306] in FortiManager and FortiPortal may allow a remote unauthenticated attacker to extract the configuration of all managed devices
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-135?
The FG-IR-24-135 vulnerability is classified as critical due to the potential for remote unauthenticated access to sensitive configuration data.
How do I fix FG-IR-24-135?
To remediate FG-IR-24-135, update FortiManager or FortiPortal to the recommended versions specified in the advisories.
Which versions of FortiManager are affected by FG-IR-24-135?
FortiManager versions 7.4.0 to 7.4.2, 7.2.0 to 7.2.5, and 7.0.0 to 7.0.12 are impacted by FG-IR-24-135.
Can FG-IR-24-135 be exploited remotely?
Yes, FG-IR-24-135 can be exploited remotely by an unauthenticated attacker to extract configurations.
What impact does FG-IR-24-135 have on system security?
FG-IR-24-135 poses a significant security risk as it allows unauthorized access to configuration details of managed devices.