← Back to browse · API

CVE-2024-47575

Severity
CRITICAL
CVSS
9.8
EPSS
0.9495
Risk score
58.23
CISA KEV
Yes
PoC
No
Published
2024-10-23
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2024-42531, GHSA-HX4Q-76P6-78CC
Products
Fortinet:FortiManager, Fortinet:FortiManager 6.2.0 ≤6.2.12, Fortinet:FortiManager 6.4.0 ≤6.4.14, Fortinet:FortiManager 7.0.0 ≤7.0.12, Fortinet:FortiManager 7.2.0 ≤7.2.7, Fortinet:FortiManager 7.4.0 ≤7.4.4, Fortinet:FortiManager 7.6.0
Sources
cisa.gov CVE-2024-47575
euvd EUVD-2024-42531

Description

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.

References