CVE-2024-47575: Fortinet FortiManager Missing Authentication Vulnerability
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.
CVE-2024-47575 is a missing authentication vulnerability in Fortinet FortiManager that affects the fgfmd daemon. A remote, unauthenticated attacker can send specially crafted requests to execute arbitrary code or commands on the device. This matters because FortiManager is commonly used to centrally manage Fortinet security appliances; compromise can give an attacker broad control over network security infrastructure and the devices it administers.
Public detail is limited to the CISA description of the flaw class and impact. Confirm all version ranges, fixed releases, and exact attack surface details against the vendor advisory before acting.
How it works
The weakness is CWE-306: Missing Authentication for Critical Function. The fgfmd daemon fails to require authentication for certain operations that should be protected. An attacker who can reach the service over the network can craft requests that the daemon processes without verifying the caller’s identity, leading to arbitrary code or command execution with the privileges of the affected process.
No public exploit mechanics or payload details are provided in the available facts. Treat any network-reachable FortiManager instance running a vulnerable configuration as potentially exposed until the vendor advisory confirms otherwise. Exploitation would typically involve unauthenticated remote access to the management plane rather than authenticated abuse or local privilege escalation.
Am I affected? How to find it in your systems
FortiManager is typically deployed as a dedicated appliance, virtual machine, or cloud instance that manages FortiGate firewalls and other Fortinet products. Inventory every FortiManager system in your environment—on-premises, virtualized, and cloud—by querying asset management databases, network management platforms, and configuration management tools for Fortinet FortiManager hosts.
- Identify systems by hostname, management IP, or product banners that indicate FortiManager.
- Check the running software version and configuration against the ranges listed in the Fortinet advisory for CVE-2024-47575; do not rely on generic version lists.
- Confirm whether the fgfmd daemon is enabled and listening on network interfaces accessible from untrusted networks.
- Review network diagrams and firewall rules for any exposure of FortiManager management ports to the internet or broad internal segments.
Telemetry signs of exploitation are not detailed in the available facts. Monitor for unexpected process creation, unusual outbound connections from FortiManager, configuration changes that were not authorized, or anomalous requests targeting the management service. Correlate with authentication logs and change-control records. Confirm specific indicators of compromise against the vendor advisory and any subsequent threat intelligence.
How to remediate
Apply the vendor-supplied update or mitigation for CVE-2024-47575 as the primary action. Follow Fortinet’s instructions exactly; CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Download and install the fixed release or patch package named in the Fortinet advisory after testing in a non-production environment where feasible.
- Verify the update completed successfully and that the fgfmd service is running the corrected code.
- After patching, re-inventory versions and confirm the vulnerable condition is closed.
- As hardening for this class of flaw, restrict management-plane access to dedicated administrative networks, enforce strong authentication and least privilege on all management interfaces, and disable unused services or features that increase attack surface.
Document the change and retain evidence of remediation for compliance and audit purposes.
If you can't patch immediately
Until the vendor update can be applied, reduce exposure with compensating controls appropriate to a missing-authentication remote code execution risk on a management platform.
- Segment FortiManager so that only authorized administrative hosts and jump servers can reach its management interfaces; block all other network paths, especially from the internet and user VLANs.
- If a web application firewall or network IPS is available, apply virtual patching rules that detect or block anomalous requests to the FortiManager management service once the vendor or reputable sources publish signatures; treat these as temporary.
- Disable or restrict the fgfmd-related functionality if the vendor documents a safe way to do so without breaking required management operations.
- Increase monitoring: alert on any connection attempts to FortiManager management ports from unexpected sources, unexpected process activity, or configuration changes. Capture and retain relevant logs for forensic review.
- If risk remains unacceptable and no mitigation is available, plan to take the system offline or replace it per CISA guidance until a fix can be applied.
If your data may have been exposed
Actively exploited missing-authentication vulnerabilities on management platforms can lead to full device compromise, lateral movement, and data exposure. Known ransomware use is not documented for this CVE. If you suspect compromise, isolate the system, preserve logs and memory if possible, and follow your incident response process. You can run a free exposure scan of your email addresses against known breach data to check whether credentials or personal information associated with your organization have appeared in prior breaches.
AICompiled with AI assistance from public sources and published under our editorial standards.
Details
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H