CVE-2024-26011

Severity
9.8CRITICAL
EPSS
0.1%
top 78.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12

Description

A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.0 through 7.0.3, FortiPortal version 6.0.0 thro

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages12 packages

NVDfortinet/fortios6.0.07.0.15+2
NVDfortinet/fortipam1.0.01.3.0
NVDfortinet/fortiproxy1.0.07.0.17+2
NVDfortinet/fortiportal5.3.06.0.15
NVDfortinet/fortimanager6.4.06.4.15+3

🔴Vulnerability Details

2
GHSA
GHSA-gm6q-h79g-j9pf: A missing authentication for critical function in Fortinet FortiManager version 72024-11-12
CVEList
CVE-2024-26011: A missing authentication for critical function in Fortinet FortiManager version 72024-11-12

📋Vendor Advisories

1
Fortinet
FortiOS - Improper authentication in fgfmd2024-11-12
CVE-2024-26011 (CRITICAL CVSS 9.8) | A missing authentication for critic | cvebase.io