FG-IR-24-423: Missing authentication in fgfmsd
A missing authentication for critical function vulnerability [CWE-306] in FortiManager fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
Reports have shown this vulnerability to be exploited in the wild.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-423?
The severity of FG-IR-24-423 is considered critical due to the potential for remote unauthenticated attackers to execute arbitrary code.
How do I fix FG-IR-24-423?
To fix FG-IR-24-423, upgrade your FortiManager or FortiManager Cloud product to the latest patched version as specified by Fortinet.
What versions of FortiManager are affected by FG-IR-24-423?
FG-IR-24-423 affects multiple versions of FortiManager, including 6.2.0 to 6.2.12, 6.4.0 to 6.4.14, 7.0.0 to 7.0.12, 7.2.0 to 7.2.7, and 7.4.1 to 7.4.4.
What is the impact of FG-IR-24-423 if exploited?
If exploited, FG-IR-24-423 can allow remote unauthenticated attackers to execute arbitrary code or commands on the affected systems.
Is FG-IR-24-423 currently being exploited in the wild?
Yes, reports have indicated that FG-IR-24-423 is being exploited in the wild.