Rewterz
SideWinder APT Group aka Rattlesnake Targeting Pakistan – Active IOCs
August 15, 2024
Rewterz
North Korean APT Kimsuky aka Black Banshee – Active IOCs
August 15, 2024

CVE-2024-21757 – Fortinet FortiManager Vulnerability

Severity

Medium

Analysis Summary

CVE-2024-21757

Fortinet FortiManager or FortiAnalyzer could allow a remote attacker to bypass security restrictions, caused by an unverified password change vulnerability. An attacker could exploit this vulnerability to allow an attacker to modify admin passwords via the device configuration backup.

Impact

  • Security Bypass

Indicators of Compromise

CVE

  • CVE-2024-21757

Affected Vendors

Fortinet

Affected Products

  • Fortinet FortiAnalyzer - 7.4.0
  • Fortinet FortiManager - 7.4.0

Remediation

Refer to FortiGuard Advisory for patch, upgrade or suggested workaround information.

FortiGuard Advisory