Tag: admin passwords remotely

Critical FortiSwitch flaw lets hackers change admin passwords remotely
News

Critical FortiSwitch flaw lets hackers change admin passwords remotely

A serious flaw in Fortinet's FortiSwitch devices that could be used to remotely alter administrator passwords has been fixed with security patches. The vulnerability (CVE-2024-48887) was found internally by Daniel Rozeboom of the FortiSwitch web UI development team, according to the business. This FortiSwitch GUI password change security issue, which has a 9.8/10 severity level, can be exploited by unauthenticated attackers in low-complexity attacks that don't involve user interaction. Threat actors can alter credentials, according to Fortinet, by sending a specially constructed request over the set_password endpoint. According to Fortinet, a remote, unauthenticated attacker could be able to change admin passwords through a carefully constructed request due to an unverified pa...