CVE Vulnerabilities

CVE-2024-21757

Published: Aug 13, 2024 | Modified: Aug 22, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.

Affected Software

Name Vendor Start Version End Version
Fortianalyzer Fortinet 7.0.0 (including) 7.0.11 (excluding)
Fortianalyzer Fortinet 7.2.0 (including) 7.2.5 (excluding)
Fortianalyzer Fortinet 7.4.0 (including) 7.4.2 (excluding)
Fortimanager Fortinet 7.0.0 (including) 7.0.11 (excluding)
Fortimanager Fortinet 7.2.0 (including) 7.2.5 (excluding)
Fortimanager Fortinet 7.4.0 (including) 7.4.2 (excluding)

References