CVE-2024-47575

Source
https://cve.org/CVERecord?id=CVE-2024-47575
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-47575.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-47575
Published
2024-10-23T15:15:30.707Z
Modified
2026-03-12T10:44:55.367167Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "6.2.0"
            },
            {
                "fixed": "6.2.13"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "6.4.0"
            },
            {
                "fixed": "6.4.15"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.0.0"
            },
            {
                "fixed": "7.0.13"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.2.0"
            },
            {
                "fixed": "7.2.8"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.4.0"
            },
            {
                "fixed": "7.4.5"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "7.6.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "6.4.1"
            },
            {
                "last_affected": "6.4.7"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.0.1"
            },
            {
                "fixed": "7.0.13"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.2.1"
            },
            {
                "fixed": "7.2.8"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.4.1"
            },
            {
                "fixed": "7.4.5"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-47575.json"