FG-IR-24-435: Unverified password change via set_password endpoint
An unverified password change vulnerability [CWE-620] in FortiSwitch GUI may allow a remote unauthenticated attacker to modify admin passwords via a specially crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-435?
The FG-IR-24-435 vulnerability is considered critical due to its potential for allowing unauthorized modification of admin passwords.
How do I fix FG-IR-24-435?
To address the FG-IR-24-435 vulnerability, upgrade FortiSwitch to version 7.6.1 or above, or the appropriate remedial version listed for your current version.
Who is affected by FG-IR-24-435?
FG-IR-24-435 affects various versions of FortiSwitch prior to the remedial updates specifically mentioned in the advisory.
What types of attacks can FG-IR-24-435 enable?
The FG-IR-24-435 vulnerability can enable remote unauthenticated attackers to change administrator passwords without proper verification.
Is authentication required to exploit FG-IR-24-435?
No, exploitation of the FG-IR-24-435 vulnerability does not require authentication, making it particularly dangerous.