cbcvebase.
CVE-2024-21757
published 2024-08-13

CVE-2024-21757: A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as…

PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
9.0th percentile
A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.

Affected

15 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer>= 7.0.0 < 7.0.117.0.11
fortinetfortianalyzer7.0.0 – 7.0.10
fortinetfortianalyzer>= 7.2.0 < 7.2.57.2.5
fortinetfortianalyzer7.2.0 – 7.2.4
fortinetfortianalyzer>= 7.4.0 < 7.4.27.4.2
fortinetfortianalyzer7.4.0 – 7.4.1
fortinetfortimanager
fortinetfortimanager>= 7.0.0 < 7.0.117.0.11
fortinetfortimanager7.0.0 – 7.0.10
fortinetfortimanager>= 7.2.0 < 7.2.57.2.5
fortinetfortimanager7.2.0 – 7.2.4
fortinetfortimanager>= 7.4.0 < 7.4.27.4.2
fortinetfortimanager7.4.0 – 7.4.1
fortinetfortinet
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.