216.73.217.172

CVE-2024-35277

· Published 14/01/2025 14:15 · Modified 31/01/2025 17:08

Labels: CVE-2024-35277 2025-01-14CVE-2024-35277CWE-306[email protected]

Essential information

Published
14/01/2025 14:15
Modified
31/01/2025 17:08
Author
Creator
CVSS
8.6 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CVSS metrics

Description

A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the managed devices by sending specifically crafted packets

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
fortinet / fortimanager cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
fortinet / fortimanager cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
fortinet / fortimanager cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
fortinet / fortimanager cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
fortinet / fortimanager cloud cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*
fortinet / fortimanager cloud cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*
fortinet / fortimanager cloud cpe:2.3:a:fortinet:fortimanager_cloud:*:*:*:*:*:*:*:*

References