cbcvebase.
CVE-2024-26011
published 2024-11-12

CVE-2024-26011: A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through…

PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.59%
44.3th percentile
A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.0 through 7.0.3, FortiPortal version 6.0.0 through 6.0.14, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted packets.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
fortinetfortimanager
fortinetfortimanager>= 6.4.0 < 6.4.156.4.15
fortinetfortimanager6.4.0 – 6.4.14
fortinetfortimanager>= 7.0.0 < 7.0.127.0.12
fortinetfortimanager7.0.0 – 7.0.11
fortinetfortimanager>= 7.2.0 < 7.2.57.2.5
fortinetfortimanager7.2.0 – 7.2.4
fortinetfortimanager>= 7.4.0 < 7.4.37.4.3
fortinetfortimanager7.4.0 – 7.4.2
fortinetfortinet
fortinetfortios
fortinetfortios>= 6.0.0 < 7.0.157.0.15
fortinetfortios6.0.0 – 6.0.18
fortinetfortios6.2.0 – 6.2.16
fortinetfortios6.4.0 – 6.4.15
fortinetfortios7.0.0 – 7.0.14
fortinetfortios>= 7.2.0 < 7.2.87.2.8
fortinetfortios7.2.0 – 7.2.7
fortinetfortios>= 7.4.0 < 7.4.47.4.4
fortinetfortios7.4.0 – 7.4.3
fortinetfortipam
fortinetfortipam
fortinetfortipam>= 1.0.0 < 1.3.01.3.0
fortinetfortipam1.0.0 – 1.0.3
fortinetfortipam1.1.0 – 1.1.2

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability resides in the fgfmd daemon (FortiGate-to-FortiManager daemon) — monitor for unauthenticated or anomalous traffic targeting the fgfmd service, which handles FGFM protocol communications.
  • Look for exploitation attempts delivered via specially crafted packets to affected Fortinet products (FortiOS, FortiManager, FortiProxy, FortiPAM, FortiPortal, FortiSwitchManager) that bypass authentication for critical functions (CWE-306: Missing Authentication for Critical Function).
  • Audit FortiManager, FortiOS, FortiProxy, FortiPAM, FortiPortal, and FortiSwitchManager instances for unexpected command execution or unauthorized configuration changes that could indicate exploitation of the missing authentication flaw.
  • ·CVSS score is 5.3 (Medium), which may cause this to be deprioritized; however, the missing authentication for a critical function (CWE-306) in widely deployed Fortinet management and gateway products warrants elevated attention in environments where these products are internet-exposed.
  • ·The vulnerability affects a broad range of Fortinet product lines and versions; ensure version inventory is accurate across FortiManager, FortiOS, FortiProxy, FortiPAM, FortiPortal, and FortiSwitchManager before scoping detection or patching efforts.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.