CVE-2024-48887
published 2025-04-08CVE-2024-48887: A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially…
PriorityP275critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
14.83%
96.3th percentile
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortiswitch | — | — |
| fortinet | fortiswitch | — | — |
| fortinet | fortiswitch | >= 6.4.0 < 6.4.15 | 6.4.15 |
| fortinet | fortiswitch | 6.4.0 – 6.4.14 | — |
| fortinet | fortiswitch | >= 7.0.0 < 7.0.11 | 7.0.11 |
| fortinet | fortiswitch | 7.0.0 – 7.0.10 | — |
| fortinet | fortiswitch | >= 7.2.0 < 7.2.9 | 7.2.9 |
| fortinet | fortiswitch | 7.2.0 – 7.2.8 | — |
| fortinet | fortiswitch | >= 7.4.0 < 7.4.5 | 7.4.5 |
| fortinet | fortiswitch | 7.4.0 – 7.4.4 | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Fortinet FortiSwitch Unauthenticated Unverified Password Change (CVE-2024-48887)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:12; content:"/change_pass"; fast_pattern; http.request_body; content:"|22|username|22|"; content:"|22|newpass|22|"; reference:url,github.com/cybersecplayground/CVE-2024-48887-FortiSwitch-Exploit; reference:cve,2024-48887; classtype:web-application-activity; sid:2061541; rev:1; metadata:attack_target Server, tls_state TLSDecrypt, created_at 2025_04_14, cve CVE_2024_48887, deployment Perimeter, deployment Internal, deployment SSLDecrypt, signature_severity Major, tag Exploit, updated_at 2025_04_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
bytes↗
|22|username|22| and |22|newpass|22| in HTTP POST body
- →Look for unauthenticated HTTP POST requests to the exact URI '/change_pass' (exactly 12 bytes) on FortiSwitch management interfaces, containing JSON fields 'username' and 'newpass' in the request body. ↗
- →The vulnerability is exploited via the 'set_password' endpoint in the FortiSwitch GUI, allowing password change without authentication. Monitor for unexpected admin password changes on FortiSwitch devices. ↗
- →MITRE mapping: TA0001 Initial Access / T1190 Exploit Public-Facing Application. Prioritize detection at perimeter and internal SSL-decrypting inspection points. ↗
- ·The Snort/Suricata rule (sid:2061541) requires TLS decryption to be effective against HTTPS-protected FortiSwitch management interfaces, as indicated by the 'tls_state TLSDecrypt' and 'deployment SSLDecrypt' metadata. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Unverified password change via set_password endpoint
vendor_fortinet·2025-04-08·CVSS 9.8
CVE-2024-48887 [CRITICAL] CWE-620 Unverified password change via set_password endpoint
FG-IR-24-435: Unverified password change via set_password endpoint
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request
CVEs: CVE-2024-48887
CWEs: CWE-620
CVSS: 9.8 (critical)
Affected products: FortiSwitch, Fortinet
GHSA
GHSA-w84w-59g8-pmg9: A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a spe
ghsa_unreviewed·2025-04-08
CVE-2024-48887 [CRITICAL] CWE-620 GHSA-w84w-59g8-pmg9: A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a spe
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request
Suricata
ET WEB_SPECIFIC_APPS Fortinet FortiSwitch Unauthenticated Unverified Password Change (CVE-2024-48887)
suricata·2025-04-14·CVSS 9.8
CVE-2024-48887 [CRITICAL] ET WEB_SPECIFIC_APPS Fortinet FortiSwitch Unauthenticated Unverified Password Change (CVE-2024-48887)
ET WEB_SPECIFIC_APPS Fortinet FortiSwitch Unauthenticated Unverified Password Change (CVE-2024-48887)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Fortinet FortiSwitch Unauthenticated Unverified Password Change (CVE-2024-48887)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:12; content:"/change_pass"; fast_pattern; http.request_body; content:"|22|username|22|"; content:"|22|newpass|22|"; reference:url,github.com/cybersecplayground/CVE-2024-48887-FortiSwitch-Exploit; reference:cve,2024-48887; classtype:web-application-activity; sid:2061541; rev:1; metadata:attack_target Server, tls_state TLSDecrypt, created_at 2025_04_14, cve CVE_2024_48887, deployment Perimeter, deployment Internal, deployment SSLDecrypt, signature_severity Major, tag Ex
No public exploits indexed.
Tenable
Reducing Remediation Time Remains a Challenge: How Tenable Vulnerability Watch Can Help
blogs_tenable·2025-04-25
Reducing Remediation Time Remains a Challenge: How Tenable Vulnerability Watch Can Help
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Critical FortiSwitch flaw lets hackers change admin passwords remotely
blogs_bleepingcomputer·2025-04-09·CVSS 7.5
CVE-2024-48887 [HIGH] Critical FortiSwitch flaw lets hackers change admin passwords remotely
## Critical FortiSwitch flaw lets hackers change admin passwords remotely
## Sergiu Gatlan
Fortinet has released security patches for a critical vulnerability in its FortiSwitch devices that can be exploited to change administrator passwords remotely.
The company says Daniel Rozeboom of the FortiSwitch web UI development team discovered the vulnerability ( CVE-2024-48887 ) internally.
Unauthenticated attackers can exploit this unverified FortiSwitch GUI password change security flaw (rated with a 9.8/10 severity score) in low-complexity attacks that don't require user interaction.
Fortinet says threat actors can change credentials using a specially crafted request sent via the set_password endpoint.
"An unverified password change vulnerability [CWE-620] in FortiSwitch GUI may allow a
Greynoiseio
NoiseLetter April 2025
blogs_greynoiseio
NoiseLetter April 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2025-04-08
Published