CVE-2024-48887

A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

Severity
Critical 9.3
CVSS 3.1
Exploited
Not listed
EPSS
0.157
96.7th percentile
Discovered by
Vendor
Vendor advisory field
Published
Apr 8, 2025
Assigned by fortinet

Description

A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

Weakness: CWE-620

Affected products

Vendor Product Category Matched by
Fortinet FortiSwitch Routing & Switching cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiSwitch

Credit

Internally discovered and reported by Daniel Rozeboom of the FortiSwitch web UI development team

Vendor remediation

Please upgrade to FortiSwitch version 7.6.1 or above Please upgrade to FortiSwitch version 7.4.5 or above Please upgrade to FortiSwitch version 7.2.9 or above Please upgrade to FortiSwitch version 7.0.11 or above Please upgrade to FortiSwitch version 6.4.15 or above

Something wrong here?