Critical FortiSwitch flaw lets hackers change admin passwords remotely
A serious flaw in Fortinet's FortiSwitch devices that could be used to remotely alter administrator passwords has been fixed with security patches.
The vulnerability (CVE-2024-48887) was found internally by Daniel Rozeboom of the FortiSwitch web UI development team, according to the business.
This FortiSwitch GUI password change security issue, which has a 9.8/10 severity level, can be exploited by unauthenticated attackers in low-complexity attacks that don't involve user interaction.
Threat actors can alter credentials, according to Fortinet, by sending a specially constructed request over the set_password endpoint.
According to Fortinet, a remote, unauthenticated attacker could be able to change admin passwords through a carefully constructed request due to an unverified pa...

