CVE-2024-47571

HIGH

Fortinet FortiManager <7.4.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials.

Scores

CVSS v3 8.1
EPSS 0.0127
EPSS Percentile 79.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-672
Status published
Products (4)
fortinet/fortimanager 6.4.12
fortinet/fortimanager 7.2.3
fortinet/fortimanager 7.4.0
fortinet/fortimanager 7.0.7 - 7.0.9
Published Jan 14, 2025
Tracked Since Feb 18, 2026