Skip to content
COOEY

EXPOSURES › CVE-2024-47575

CVE-2024-47575

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-10-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-47575 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Fortinet FortiManager allows remote, unauthenticated attackers to execute arbitrary code via a missing authentication flaw in the fgfmd daemon.

This missing authentication vulnerability enables remote code execution without credentials, posing a severe risk to network management systems and allowing attackers to compromise the entire infrastructure. DIB organizations must immediately patch this flaw to prevent unauthorized access to critical management interfaces and potential lateral movement.

Shame score — A critical RCE vulnerability in a core management product that allows unauthenticated remote code execution represents a severe security failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.