9.8

CVE-2024-48887

Media report

A  unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
FortinetFortiswitch Version >= 6.4.0 < 6.4.15
FortinetFortiswitch Version >= 7.0.0 < 7.0.11
FortinetFortiswitch Version >= 7.2.0 < 7.2.9
FortinetFortiswitch Version >= 7.4.0 < 7.4.5
FortinetFortiswitch Version7.6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.14% 0.351
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
psirt@fortinet.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-620 Unverified Password Change

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.