Vulnerability details
Advisory: SB2024102360 - Remote command execution in Fortinet FortiManager
Vulnerable component: FortiManager
CVE-ID: CVE-2024-47575
CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H/RL:O/RC:C
CWE-ID: CWE-306 - Missing Authentication for Critical Function
Description:
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authentication in FortiManager fgfmd daemon. A remote non-authenticated attacker can send specially crafted requests to the system and execute arbitrary commands, resulting in full system compromise.
Note, the vulnerability is being actively exploited in the wild.
External links:
https://www.fortiguard.com/psirt/FG-IR-24-423