CVE Vulnerabilities

CVE-2024-48887

Unverified Password Change

Published: Apr 08, 2025 | Modified: Jul 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

Weakness

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Affected Software

Name Vendor Start Version End Version
Fortiswitch Fortinet 6.4.0 (including) 6.4.15 (excluding)
Fortiswitch Fortinet 7.0.0 (including) 7.0.11 (excluding)
Fortiswitch Fortinet 7.2.0 (including) 7.2.9 (excluding)
Fortiswitch Fortinet 7.4.0 (including) 7.4.5 (excluding)
Fortiswitch Fortinet 7.6.0 (including) 7.6.0 (including)

Potential Mitigations

References