CVE-2024-45329

A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.8 may allow an authenticated attacker to view un

Severity
Low 3.9
CVSS 3.1
Exploited
Not listed
EPSS
0.003
25.4th percentile
Discovered by
Third party
Vendor advisory field
Published
Jun 10, 2025
Assigned by fortinet

Description

A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.8 may allow an authenticated attacker to view unauthorized device information via key modification in API requests.

Weakness: CWE-639

Affected products

Vendor Product Category Matched by
Fortinet FortiPortal Network & Security Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiPortal

Credit

Fortinet is pleased to thank Pablo Castillo Andreu and Antonio Moreno from Telefonica Tech for reporting this vulnerability under responsible disclosure.

Vendor remediation

Please upgrade to FortiPortal version 7.4.1 or above Please upgrade to FortiPortal version 7.2.6 or above Please upgrade to FortiPortal version 7.0.9 or above

Something wrong here?