CVE-2024-21757
published 2024-08-13CVE-2024-21757: A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as…
PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
9.0th percentile
A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | >= 7.0.0 < 7.0.11 | 7.0.11 |
| fortinet | fortianalyzer | 7.0.0 – 7.0.10 | — |
| fortinet | fortianalyzer | >= 7.2.0 < 7.2.5 | 7.2.5 |
| fortinet | fortianalyzer | 7.2.0 – 7.2.4 | — |
| fortinet | fortianalyzer | >= 7.4.0 < 7.4.2 | 7.4.2 |
| fortinet | fortianalyzer | 7.4.0 – 7.4.1 | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 7.0.0 < 7.0.11 | 7.0.11 |
| fortinet | fortimanager | 7.0.0 – 7.0.10 | — |
| fortinet | fortimanager | >= 7.2.0 < 7.2.5 | 7.2.5 |
| fortinet | fortimanager | 7.2.0 – 7.2.4 | — |
| fortinet | fortimanager | >= 7.4.0 < 7.4.2 | 7.4.2 |
| fortinet | fortimanager | 7.4.0 – 7.4.1 | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Priviledged admin able to modify super-admins password
vendor_fortinet·2024-08-13·CVSS 6.1
CVE-2024-21757 [MEDIUM] CWE-620 Priviledged admin able to modify super-admins password
FG-IR-23-467: Priviledged admin able to modify super-admins password
A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.
CVEs: CVE-2024-21757
CWEs: CWE-620
CVSS: 6.1 (medium)
Affected products: FortiAnalyzer, FortiManager, Fortinet
GHSA
GHSA-q5q5-qr9g-74ch: A unverified password change in Fortinet FortiManager versions 7
ghsa_unreviewed·2024-08-13
CVE-2024-21757 [MEDIUM] CWE-620 GHSA-q5q5-qr9g-74ch: A unverified password change in Fortinet FortiManager versions 7
A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-13
Published