cbcvebase.
CVE-2024-47571
published 2025-01-14

CVE-2024-47571: An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate…

PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.88%
54.8th percentile
An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials.

Affected

8 ranges
VendorProductVersion rangeFixed in
fortinetfortigate
fortinetfortimanager
fortinetfortimanager
fortinetfortimanager
fortinetfortimanager
fortinetfortimanager>= 7.0.7 < 7.0.97.0.9
fortinetfortimanager7.0.7 – 7.0.8
fortinetfortinet

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for successful authentication to FortiGate using credentials belonging to admin accounts that have been deleted in FortiManager — the vulnerability allows deleted accounts to persist and remain usable for access.
  • Audit FortiGate admin account lists against FortiManager's current active account list; any FortiGate admin account that no longer exists in FortiManager but can still authenticate represents exploitation of this vulnerability.
  • ·Affected versions are FortiManager 6.4.12 through 7.4.0; verify your FortiManager version falls within this range before applying detections or mitigations.
  • ·The vulnerability is rooted in CWE-672 (Operation on a Resource after Expiration or Release), meaning deleted admin accounts are not properly invalidated — access control enforcement on FortiGate does not reflect account deletion events from FortiManager.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.