CVE-2024-47575: Fortinet FortiManager Missing Authentication Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-10-23. EPSS: 94.8% chance of exploitation in the next 30 days.

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.

Affected products

  • Fortinet FortiManager: from 6.2.0, before 6.2.13 (fixed in 6.2.13); from 6.4.0, before 6.4.15 (fixed in 6.4.15); from 7.0.0, before 7.0.13 (fixed in 7.0.13); from 7.2.0, before 7.2.8 (fixed in 7.2.8); from 7.4.0, before 7.4.5 (fixed in 7.4.5); version 7.6.0 only
  • Fortinet FortiManager Cloud: from 6.4.1, up to and including 6.4.7; from 7.0.1, before 7.0.13 (fixed in 7.0.13); from 7.2.1, before 7.2.8 (fixed in 7.2.8); from 7.4.1, before 7.4.5 (fixed in 7.4.5)

Published 2024-10-23. Last modified 2026-06-17.