A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the managed devices by sending specifically crafted packets
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-135 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
31 Jan 2025, 17:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-135 - Vendor Advisory | |
First Time |
Fortinet fortimanager Cloud
Fortinet Fortinet fortimanager |
|
CPE | cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
14 Jan 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-14 14:15
Updated : 2025-01-31 17:08
NVD link : CVE-2024-35277
Mitre link : CVE-2024-35277
JSON object : View
Products Affected
fortinet
- fortimanager_cloud
- fortimanager
CWE
CWE-306
Missing Authentication for Critical Function