Cythera Cyber Security

FortiManager API Vulnerability - CVE-2024-47575

Fortinet has disclosed a critical vulnerability in the FortiManager API, identified as CVE-2024-47575. This vulnerability is currently being exploited in the wild to steal sensitive data.
Talk to an expert

FortiManager API Vulnerability

CVE: CVE-2024-47575

CVSS: 9.8/10

What is Vulnerable:

Multiple versions of FortiManager are affected by this newly discovered zero-day vulnerability.

Affected Versions:

• FortiManager 7.6

• FortiManager 7.4

• FortiManager 7.2

• FortiManager 7.0

• FortiManager 6.4

• FortiManager 6.2

• FortiManager Cloud 7.6

• FortiManager Cloud 7.4

• FortiManager Cloud 7.2

• FortiManager Cloud 7.0

• FortiManager Cloud 6.4

What is Happening

Fortinet has disclosed a critical vulnerability in the FortiManager API, identified as CVE-2024-47575.
This vulnerability is currently being exploited in the wild to steal sensitive data, including configuration files, IP addresses, and managed device credentials.
Details are available here: fortiguard.com 

Key Facts

-  Fortinet have advised that this is being actively exploited in the wild.
- "A missing authentication for a critical function vulnerability [CWE-306] in the FortiManager fgfmd daemon may allow a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests."

What You Can Do

Fortinet has released patches to address this vulnerability. For more information on upgrading, please refer to Fortinet’s upgrade advisory table here.
Cythera strongly recommends patching your Fortimanager instances on an emergency basis.


Events

Latest events

Join Cythera experts for networking events, technical briefings, and hands-on workshops hosted throughout the year.
View all events
No items found.
Cyber security news

Latest advisories

Stay ahead of emerging threats with our expert blog posts, research, and industry updates.
Silverstripe - Host Header Injection
Silverstripe CMS is affected by a Host Header Injection flaw, which can be exploited to manipulate password reset workflows, potentially redirecting or compromising user data.
FarCry Core Framework - Multiple Issues
FarCry Core contains multiple vulnerabilities that could let unauthenticated users upload arbitrary files and execute remote code on the hosting server.
Silverstripe – Cross-Site Scripting (XSS) Vulnerability
With local organisation admin credentials, an attacker can exploit the API to create, delete, or revert virtual machine snapshots in other organisations’ Virtual Data Centres (VDCs), breaching isolation boundaries.