EXPOSURES › CVE-2024-47575
CVE-2024-47575
HIGH ⌖ ON CISA KEV · EXPLOITEDFortinet FortiManager allows remote, unauthenticated attackers to execute arbitrary code via a missing authentication flaw in the fgfmd daemon.
This missing authentication vulnerability enables remote code execution without credentials, posing a severe risk to network management systems and allowing attackers to compromise the entire infrastructure. DIB organizations must immediately patch this flaw to prevent unauthorized access to critical management interfaces and potential lateral movement.
Shame score — A critical RCE vulnerability in a core management product that allows unauthenticated remote code execution represents a severe security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.