9.8

CVE-2024-26011

A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.0 through 7.0.3, FortiPortal version 6.0.0 through 6.0.14, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ FortiOS Version >= 6.0.0 < 7.0.15
Fortinet ≫ FortiOS Version >= 7.2.0 < 7.2.8
Fortinet ≫ FortiOS Version >= 7.4.0 < 7.4.4
Fortinet ≫ Fortipam Version >= 1.0.0 < 1.3.0
Fortinet ≫ FortiProxy Version >= 1.0.0 < 7.0.17
Fortinet ≫ FortiProxy Version >= 7.2.0 < 7.2.10
Fortinet ≫ FortiProxy Version >= 7.4.0 < 7.4.4
Fortinet ≫ Fortimanager Version >= 6.4.0 < 6.4.15
Fortinet ≫ Fortimanager Version >= 7.0.0 < 7.0.12
Fortinet ≫ Fortimanager Version >= 7.2.0 < 7.2.5
Fortinet ≫ Fortimanager Version >= 7.4.0 < 7.4.3
Fortinet ≫ FortiSwitch Manager Version >= 7.0.0 < 7.0.4
Fortinet ≫ FortiSwitch Manager Version >= 7.2.0 < 7.2.4
Fortinet ≫ Fortiportal Version >= 5.3.0 < 6.0.15
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.46
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Fortinet 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

https://fortiguard.fortinet.com/psirt/FG-IR-24-032
Vendor Advisory