CVE-2024-26011
published 2024-11-12CVE-2024-26011: A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.59%
44.3th percentile
A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.0 through 7.0.3, FortiPortal version 6.0.0 through 6.0.14, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted packets.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 6.4.0 < 6.4.15 | 6.4.15 |
| fortinet | fortimanager | 6.4.0 – 6.4.14 | — |
| fortinet | fortimanager | >= 7.0.0 < 7.0.12 | 7.0.12 |
| fortinet | fortimanager | 7.0.0 – 7.0.11 | — |
| fortinet | fortimanager | >= 7.2.0 < 7.2.5 | 7.2.5 |
| fortinet | fortimanager | 7.2.0 – 7.2.4 | — |
| fortinet | fortimanager | >= 7.4.0 < 7.4.3 | 7.4.3 |
| fortinet | fortimanager | 7.4.0 – 7.4.2 | — |
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.0.0 < 7.0.15 | 7.0.15 |
| fortinet | fortios | 6.0.0 – 6.0.18 | — |
| fortinet | fortios | 6.2.0 – 6.2.16 | — |
| fortinet | fortios | 6.4.0 – 6.4.15 | — |
| fortinet | fortios | 7.0.0 – 7.0.14 | — |
| fortinet | fortios | >= 7.2.0 < 7.2.8 | 7.2.8 |
| fortinet | fortios | 7.2.0 – 7.2.7 | — |
| fortinet | fortios | >= 7.4.0 < 7.4.4 | 7.4.4 |
| fortinet | fortios | 7.4.0 – 7.4.3 | — |
| fortinet | fortipam | — | — |
| fortinet | fortipam | — | — |
| fortinet | fortipam | >= 1.0.0 < 1.3.0 | 1.3.0 |
| fortinet | fortipam | 1.0.0 – 1.0.3 | — |
| fortinet | fortipam | 1.1.0 – 1.1.2 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability resides in the fgfmd daemon (FortiGate-to-FortiManager daemon) — monitor for unauthenticated or anomalous traffic targeting the fgfmd service, which handles FGFM protocol communications. ↗
- →Look for exploitation attempts delivered via specially crafted packets to affected Fortinet products (FortiOS, FortiManager, FortiProxy, FortiPAM, FortiPortal, FortiSwitchManager) that bypass authentication for critical functions (CWE-306: Missing Authentication for Critical Function). ↗
- →Audit FortiManager, FortiOS, FortiProxy, FortiPAM, FortiPortal, and FortiSwitchManager instances for unexpected command execution or unauthorized configuration changes that could indicate exploitation of the missing authentication flaw. ↗
- ·CVSS score is 5.3 (Medium), which may cause this to be deprioritized; however, the missing authentication for a critical function (CWE-306) in widely deployed Fortinet management and gateway products warrants elevated attention in environments where these products are internet-exposed. ↗
- ·The vulnerability affects a broad range of Fortinet product lines and versions; ensure version inventory is accurate across FortiManager, FortiOS, FortiProxy, FortiPAM, FortiPortal, and FortiSwitchManager before scoping detection or patching efforts. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
FortiOS - Improper authentication in fgfmd
vendor_fortinet·2024-11-12·CVSS 5.3
CVE-2024-26011 [MEDIUM] CWE-306 FortiOS - Improper authentication in fgfmd
FG-IR-24-032: FortiOS - Improper authentication in fgfmd
A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.0 through 7.0.3, FortiPortal version 6.0.0 through 6.0.14, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted packet
GHSA
GHSA-gm6q-h79g-j9pf: A missing authentication for critical function in Fortinet FortiManager version 7
ghsa_unreviewed·2024-11-12
CVE-2024-26011 [MEDIUM] CWE-306 GHSA-gm6q-h79g-j9pf: A missing authentication for critical function in Fortinet FortiManager version 7
A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.0 through 7.0.3, FortiPortal version 6.0.0 through 6.0.14, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted packets.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-12
Published