CVE Vulnerabilities

CVE-2024-48887

Unverified Password Change

Published: Apr 08, 2025 | Modified: Jul 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

Weakness

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Affected Software

NameVendorStart VersionEnd Version
FortiswitchFortinet6.4.0 (including)6.4.15 (excluding)
FortiswitchFortinet7.0.0 (including)7.0.11 (excluding)
FortiswitchFortinet7.2.0 (including)7.2.9 (excluding)
FortiswitchFortinet7.4.0 (including)7.4.5 (excluding)
FortiswitchFortinet7.6.0 (including)7.6.0 (including)

Potential Mitigations

References