Tag: FortiManager

Fortinet Warns of Critical Vulnerability in FortiManager Under Active Exploitation
News

Fortinet Warns of Critical Vulnerability in FortiManager Under Active Exploitation

Details of a serious security vulnerability affecting FortiManager that has been actively exploited in the wild have been verified by Fortinet. The vulnerability, also known as FortiJump, is rooted in the FortiGate to FortiManager (FGFM) protocol and is tracked as CVE-2024-47575 (CVSS score: 9.8). According to the company's statement on Wednesday, a remote, unauthenticated attacker might use specifically constructed requests to execute arbitrary code or commands due to a critical function vulnerability [CWE-306] in the FortiManager fgfmd daemon that lacks authentication. FortiManager versions 7.x, 6.x, and FortiManager Cloud 7.x and 6.x are affected by the flaw. It impacts older FortiAnalyzer models as well read more about Fortinet Warns of Critical Vulnerability in FortiManager ...