CVE-2024-47573

An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 and below, version 7.0.6 and below may allow an auth

Severity
Medium 6
CVSS 3.1
Exploited
Not listed
EPSS
0.002
12.0th percentile
Discovered by
Vendor
Vendor advisory field
Published
Mar 14, 2025
Assigned by fortinet

Description

An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 and below, version 7.0.6 and below may allow an authenticated attacker with at least Read/Write permission on system maintenance to install a corrupted firmware image.

Weakness: CWE-354

Affected products

Vendor Product Category Matched by
Fortinet FortiNDR Threat Detection & Sandbox cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiNDR

Credit

Internally discovered and reported by Dipanjan Das from FortiGuard Research team.

Vendor remediation

Please upgrade to FortiNDR version 7.4.3 or above Please upgrade to FortiNDR version 7.2.2 or above

Something wrong here?