Zero-day vulnerability in FortiManager

Missing authentication for critical function
CVE-2024-47575

Vulnerability details

Advisory: SB2024102360 - Remote command execution in Fortinet FortiManager

Vulnerable component: FortiManager

CVE-ID: CVE-2024-47575

CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-306 - Missing Authentication for Critical Function

Description:

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to missing authentication in FortiManager fgfmd daemon. A remote non-authenticated attacker can send specially crafted requests to the system and execute arbitrary commands, resulting in full system compromise.

Note, the vulnerability is being actively exploited in the wild.

External links:

https://www.fortiguard.com/psirt/FG-IR-24-423