CVE-2024-35277

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 306

Summary

CVE-2024-35277 is a vulnerability affecting Fortinet FortiPortal versions 6.0.0 through 6.0.15, FortiManager versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, and 6.4.0 through 6.4.14. This issue results from a missing authentication for a critical function. An attacker can exploit this vulnerability by sending specifically crafted packets, granting unauthorized access to the configuration of managed devices. Successful exploitation could lead to significant security consequences, including unauthorized device configuration changes. Fortinet urges users to apply the available patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share