CVE Vulnerabilities

CVE-2024-47571

Operation on a Resource after Expiration or Release

Published: Jan 14, 2025 | Modified: Mar 19, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials.

Weakness

The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.

Affected Software

Name Vendor Start Version End Version
Fortimanager Fortinet 7.0.7 (including) 7.0.9 (excluding)
Fortimanager Fortinet 6.4.12 (including) 6.4.12 (including)
Fortimanager Fortinet 7.2.3 (including) 7.2.3 (including)
Fortimanager Fortinet 7.4.0 (including) 7.4.0 (including)

References