FG-IR-24-239: Admin Account Persistence after Deletion
An operation on a resource after expiration or release vulnerability [CWE-672] in FortiManager may allow a Fortigate admin account that is deleted through FortiManager to still be able to login to the FortiGate via valid credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-239?
The severity of FG-IR-24-239 is significant as it allows deleted Fortigate admin accounts to still log in with valid credentials.
How do I fix FG-IR-24-239?
To fix FG-IR-24-239, update FortiManager to the latest version that addresses this vulnerability.
Which versions of FortiManager are affected by FG-IR-24-239?
FG-IR-24-239 affects FortiManager versions prior to 7.4.1, 7.2.4, 7.0.9, and 6.4.13.
What type of vulnerability is FG-IR-24-239?
FG-IR-24-239 is classified as an operation on a resource after expiration or release vulnerability.
Can a deleted Fortigate admin account access FortiGate systems after FG-IR-24-239?
Yes, a deleted Fortigate admin account can still access FortiGate systems if the vulnerability FG-IR-24-239 is present.