CVE-2024-48887
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request
Severity
Critical 9.3
CVSS 3.1
Exploited
Not listed
EPSS
0.157
96.7th percentile
Discovered by
Vendor
Vendor advisory field
Published
Apr 8, 2025
Assigned by fortinet
Description
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request
Weakness: CWE-620
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSwitch | Routing & Switching | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiSwitch
Credit
Internally discovered and reported by Daniel Rozeboom of the FortiSwitch web UI development team
Vendor remediation
Please upgrade to FortiSwitch version 7.6.1 or above Please upgrade to FortiSwitch version 7.4.5 or above Please upgrade to FortiSwitch version 7.2.9 or above Please upgrade to FortiSwitch version 7.0.11 or above Please upgrade to FortiSwitch version 6.4.15 or above