LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-47575: Fortinet FortiManager Missing Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 23, 2024
CVSS 9.8 · Critical⚠ Actively exploited (CISA KEV)
9.8
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Nov 13, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-47575 to its Known Exploited Vulnerabilities catalog on Oct 23, 2024, with a federal patch deadline of Nov 13, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.

CVE-2024-47575 is a missing authentication vulnerability in Fortinet FortiManager that affects the fgfmd daemon. A remote, unauthenticated attacker can send specially crafted requests to execute arbitrary code or commands on the device. This matters because FortiManager is commonly used to centrally manage Fortinet security appliances; compromise can give an attacker broad control over network security infrastructure and the devices it administers.

Public detail is limited to the CISA description of the flaw class and impact. Confirm all version ranges, fixed releases, and exact attack surface details against the vendor advisory before acting.

How it works

The weakness is CWE-306: Missing Authentication for Critical Function. The fgfmd daemon fails to require authentication for certain operations that should be protected. An attacker who can reach the service over the network can craft requests that the daemon processes without verifying the caller’s identity, leading to arbitrary code or command execution with the privileges of the affected process.

No public exploit mechanics or payload details are provided in the available facts. Treat any network-reachable FortiManager instance running a vulnerable configuration as potentially exposed until the vendor advisory confirms otherwise. Exploitation would typically involve unauthenticated remote access to the management plane rather than authenticated abuse or local privilege escalation.

Am I affected? How to find it in your systems

FortiManager is typically deployed as a dedicated appliance, virtual machine, or cloud instance that manages FortiGate firewalls and other Fortinet products. Inventory every FortiManager system in your environment—on-premises, virtualized, and cloud—by querying asset management databases, network management platforms, and configuration management tools for Fortinet FortiManager hosts.

Telemetry signs of exploitation are not detailed in the available facts. Monitor for unexpected process creation, unusual outbound connections from FortiManager, configuration changes that were not authorized, or anomalous requests targeting the management service. Correlate with authentication logs and change-control records. Confirm specific indicators of compromise against the vendor advisory and any subsequent threat intelligence.

How to remediate

Apply the vendor-supplied update or mitigation for CVE-2024-47575 as the primary action. Follow Fortinet’s instructions exactly; CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Document the change and retain evidence of remediation for compliance and audit purposes.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to a missing-authentication remote code execution risk on a management platform.

If your data may have been exposed

Actively exploited missing-authentication vulnerabilities on management platforms can lead to full device compromise, lateral movement, and data exposure. Known ransomware use is not documented for this CVE. If you suspect compromise, isolate the system, preserve logs and memory if possible, and follow your incident response process. You can run a free exposure scan of your email addresses against known breach data to check whether credentials or personal information associated with your organization have appeared in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · FortiManager
WeaknessCWE-306
CVSS base score9.8 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
PublishedOct 23, 2024
Added to CISA KEVOct 23, 2024
Federal patch deadlineNov 13, 2024
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities