cbcvebase.
CVE-2024-48887
published 2025-04-08

CVE-2024-48887: A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

Affected

11 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortiswitch
fortinetfortiswitch
fortinetfortiswitch>= 6.4.0 < 6.4.156.4.15
fortinetfortiswitch6.4.0 – 6.4.14
fortinetfortiswitch>= 7.0.0 < 7.0.117.0.11
fortinetfortiswitch7.0.0 – 7.0.10
fortinetfortiswitch>= 7.2.0 < 7.2.97.2.9
fortinetfortiswitch7.2.0 – 7.2.8
fortinetfortiswitch>= 7.4.0 < 7.4.57.4.5
fortinetfortiswitch7.4.0 – 7.4.4