CVE-2024-47575
KEV PoC moderate2Unauthenticated RCE in Fortinet FortiManager and FortiManager Cloud
CISA: Fortinet FortiManager Missing Authentication Vulnerability
CVE-2024-47575 is a missing-authentication flaw (CWE-306) in Fortinet FortiManager and FortiManager Cloud, rated critical at CVSS 9.8. An unauthenticated remote attacker can send specially crafted requests to the affected management interface and execute arbitrary code or commands, with no credentials, privileges, or user interaction required. Every supported FortiManager branch from 6.2 through 7.6 and four FortiManager Cloud branches are affected, meaning any organization using these products as the central management plane for FortiGate firewalls is exposed, and compromise of the appliance can provide a foothold across the entire managed firewall estate. The flaw was exploited as a zero-day in an active campaign before patches were available, was added to CISA KEV on 2024-10-23 (ransomware use not yet confirmed), and carries a 95.1% EPSS probability of exploitation within 30 days.
What to do: Upgrade FortiManager and FortiManager Cloud to the fixed releases listed in Fortinet advisory FG-IR-24-423 (FortiManager 7.6.1+, 7.4.5+, 7.2.8+, 7.0.13+, 6.4.15+, or 6.2.13+; Cloud 7.4.5+, 7.2.8+, 7.0.13+, or 6.4.8+), or apply the interim mitigations of restricting which IP addresses may connect to the fgfm service, disabling fgfm where it is not required, and applying the vendor's IPS signature. Hunt logs for signs of exploitation, such as unexpected fgfm requests, unknown IPs, or unexplained device registrations on the FortiManager. As a CISA KEV entry, federal agencies and other CISA-directed organizations must apply the mitigations or discontinue use of the product by the required deadline.
| Fortinet FortiManager | 7.6.0 |
| Fortinet FortiManager | 7.4.0 through 7.4.4 |
| Fortinet FortiManager | 7.2.0 through 7.2.7 |
| Fortinet FortiManager | 7.0.0 through 7.0.12 |
| Fortinet FortiManager | 6.4.0 through 6.4.14 |
| Fortinet FortiManager | 6.2.0 through 6.2.12 |
| Fortinet FortiManager Cloud | 7.4.1 through 7.4.4 |
| Fortinet FortiManager Cloud | 7.2.1 through 7.2.7 |
| Fortinet FortiManager Cloud | 7.0.1 through 7.0.12 |
| Fortinet FortiManager Cloud | 6.4.1 through 6.4.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.
- Affected
- Fortinet FortiManager
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- fortinet
- Products
- fortimanager, fortimanager cloud
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H