CVE-2024-47571
published 2025-01-14CVE-2024-47571: An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.88%
54.8th percentile
An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortigate | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 7.0.7 < 7.0.9 | 7.0.9 |
| fortinet | fortimanager | 7.0.7 – 7.0.8 | — |
| fortinet | fortinet | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for successful authentication to FortiGate using credentials belonging to admin accounts that have been deleted in FortiManager — the vulnerability allows deleted accounts to persist and remain usable for access. ↗
- →Audit FortiGate admin account lists against FortiManager's current active account list; any FortiGate admin account that no longer exists in FortiManager but can still authenticate represents exploitation of this vulnerability. ↗
- ·Affected versions are FortiManager 6.4.12 through 7.4.0; verify your FortiManager version falls within this range before applying detections or mitigations. ↗
- ·The vulnerability is rooted in CWE-672 (Operation on a Resource after Expiration or Release), meaning deleted admin accounts are not properly invalidated — access control enforcement on FortiGate does not reflect account deletion events from FortiManager. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Admin Account Persistence after Deletion
vendor_fortinet·2025-01-14·CVSS 8.1
CVE-2024-47571 [HIGH] CWE-672 Admin Account Persistence after Deletion
FG-IR-24-239: Admin Account Persistence after Deletion
An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials.
CVEs: CVE-2024-47571
CWEs: CWE-672
CVSS: 8.1 (high)
Affected products: FortiGate, FortiManager, Fortinet
GHSA
GHSA-44m6-q7g6-5vp6: An operation on a resource after expiration or release in Fortinet FortiManager 6
ghsa_unreviewed·2025-01-14
CVE-2024-47571 [HIGH] CWE-672 GHSA-44m6-q7g6-5vp6: An operation on a resource after expiration or release in Fortinet FortiManager 6
An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-14
Published