U.S. CISA adds Fortinet FortiManager flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-47575 | Unauthenticated RCE in Fortinet FortiManager and FortiManager Cloud CVE-2024-47575 is a missing-authentication flaw (CWE-306) in Fortinet FortiManager and FortiManager Cloud, rated critical at CVSS 9.8. An unauthenticated remote attacker can send specially crafted requests to the affected management interface and execute arbitrary code or commands, with no credentials, privileges, or user interaction required. Every supported FortiManager branch from 6.2 through 7.6 and four FortiManager Cloud branches are affected, meaning any organization using these products as the central management plane for FortiGate firewalls is exposed, and compromise of the appliance can provide a foothold across the entire managed firewall estate. The flaw was exploited as a zero-day in an active campaign before patches were available, was added to CISA KEV on 2024-10-23 (ransomware use not yet confirmed), and carries a 95.1% EPSS probability of exploitation within 30 days. Do: Upgrade FortiManager and FortiManager Cloud to the fixed releases listed in Fortinet advisory FG-IR-24-423 (FortiManager 7.6.1+, 7.4.5+, 7.2.8+, 7.0.13+, 6.4.15+, or 6.2.13+; Cloud 7.4.5+, 7.2.8+, 7.0.13+, or 6.4.8+), or apply the interim mitigations of restricting which IP addresses may connect to the fgfm service, disabling fgfm where it is not required, and applying the vendor's IPS signature. Hunt logs for signs of exploitation, such as unexpected fgfm requests, unknown IPs, or unexplained device registrations on the FortiManager. As a CISA KEV entry, federal agencies and other CISA-directed organizations must apply the mitigations or discontinue use of the product by the required deadline. | 9.8 | 95% | KEV PoC |
| moderate≈5,000 internet-exposed FortiManager/Cloud instances (order of thousands); total on-prem deployments likely higher |
Full article455 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiManager flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Fortinet FortiManager missing authentication vulnerability CVE-2024-47575 (CVSS v4 score: 9.8) to its Known Exploited Vulnerabilities (KEV) catalog.
A missing authentication flaw in FortiManager and FortiManager Cloud versions allows attackers to execute arbitrary code or commands through specially crafted requests.
“A missing authentication for critical function vulnerability [CWE-306] in FortiManager fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.” reads the advisory published by Fortinet.
Fortinet confirmed that the vulnerability CVE-2024-47575 has been exploited in the wild
“Reports have shown this vulnerability to be exploited in the wild,” continues the advisory. “The identified actions of this attack in the wild have been to automate via a script the exfiltration of various files from the FortiManager which contained the IPs, credentials and configurations of the managed devices,” Fortinet added.
The company hasn’t received reports of attacks exploiting the flaw to deploy malware or backdoors on compromised FortiManager systems.
“At this stage, we have not received reports of any low-level system installations of malware or backdoors on these compromised FortiManager systems. To the best of our knowledge, there have been no indicators of modified databases, or connections and modifications to the managed devices.” states the advisory.
The vulnerability impacts the following versions:
| Version | Affected | Solution |
|---|---|---|
| FortiManager 7.6 | 7.6.0 | Upgrade to 7.6.1 or above |
| FortiManager 7.4 | 7.4.0 through 7.4.4 | Upgrade to 7.4.5 or above |
| FortiManager 7.2 | 7.2.0 through 7.2.7 | Upgrade to 7.2.8 or above |
| FortiManager 7.0 | 7.0.0 through 7.0.12 | Upgrade to 7.0.13 or above |
| FortiManager 6.4 | 6.4.0 through 6.4.14 | Upgrade to 6.4.15 or above |
| FortiManager 6.2 | 6.2.0 through 6.2.12 | Upgrade to 6.2.13 or above |
| FortiManager Cloud 7.6 | Not affected | Not Applicable |
| FortiManager Cloud 7.4 | 7.4.1 through 7.4.4 | Upgrade to 7.4.5 or above |
| FortiManager Cloud 7.2 | 7.2.1 through 7.2.7 | Upgrade to 7.2.8 or above |
| FortiManager Cloud 7.0 | 7.0.1 through 7.0.12 | Upgrade to 7.0.13 or above |
| FortiManager Cloud 6.4 | 6.4 all versions | Migrate to a fixed release |
Fortinet published IOCs to detect exploitation attempts of this issue and provided workarounds to mitigate the risk of attacks exploiting this vulnerability.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by November 13, 2024.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – Fortinet FortiManager, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/170175/hacking/us-cisa-adds-fortinet-fortimanager-flaw-known-exploited-vulnerabilities-catalog.html