Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-47575

CVSS 9.8 · Critical KEV EPSS 93.87% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-47575

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
关键功能的认证机制缺失
Source: NVD (National Vulnerability Database)
Vulnerability Title
Fortinet FortiManager 访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Fortinet FortiManager是美国飞塔(Fortinet)公司的一套集中化网络安全管理平台。该平台支持集中管理任意数量的Fortinet设备,并能够将设备分组到不同的管理域(ADOM)进一步简化多设备安全部署与管理。 Fortinet FortiManager存在访问控制错误漏洞,该漏洞源于缺少关键功能的身份验证,允许攻击者通过特制的请求执行任意代码或命令。以下产品及版本受到影响:FortiManager 7.6.0版本;FortiManager 7.4.4版本及之前的7.4.x版本;For
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
FortinetFortiManager 7.6.0 cpe:2.3:o:fortinet:fortimanager:7.6.0:*:*:*:*:*:*:*

II. Public POCs for CVE-2024-47575

#POC DescriptionSource LinkShenlong Link
1Nonehttps://github.com/maybelookis/CVE-2024-47575POC Details
2Nonehttps://github.com/HazeLook/CVE-2024-47575POC Details
3Nonehttps://github.com/Jaden1419/CVE-2024-47575POC Details
4Nonehttps://github.com/hatvix1/CVE-2024-47575POC Details
5Nonehttps://github.com/hazesecurity/CVE-2024-47575POC Details
6CVE-2024-47575: Critical Remote Code Execution (RCE) Vulnerability in VMware Horizonhttps://github.com/groshi/CVE-2024-47575-POCPOC Details
7CVE-2024-47575 POChttps://github.com/zgimszhd61/CVE-2024-47575-POCPOC Details
8Nonehttps://github.com/ShawtyTwo/CVE-2024-47575POC Details
9CVE-2024-47575: FortiManager Missing Authenticationhttps://github.com/Fruktolzzz/CVE-2024-47575POC Details
10Nonehttps://github.com/krmxd/CVE-2024-47575POC Details
11CVE-2024-47575: FortiManager Missing Authenticationhttps://github.com/groshi324/CVE-2024-47575POC Details
12CVE-2024-47575: FortiManager Missing Authenticationhttps://github.com/VIRKiss/CVE-2024-47575POC Details
13CVE-2024-47575: FortiManager Missing Authenticationhttps://github.com/Jomq12/CVE-2024-47575POC Details
14CVE-2024-47575: FortiManager Missing Authenticationhttps://github.com/youngwhale21/CVE-2024-47575POC Details
15CVE-2024-47575: FortiManager Missing Authenticationhttps://github.com/gifretg/CVE-2024-47575POC Details
16CVE-2024-47575: FortiManager Missing Authenticationhttps://github.com/LayNMR/CVE-2024-47575POC Details
17CVE-2024-47575: FortiManager Missing Authenticationhttps://github.com/TaliBander/CVE-2024-47575POC Details
18CVE-2024-47575: FortiManager Missing Authenticationhttps://github.com/WotleAks/CVE-2024-47575POC Details
19 CVE-2024-47575: FortiManager Missing Authenticationhttps://github.com/DaresNone/CVE-2024-47575POC Details
20Fortimanager Unauthenticated Remote Code Execution AKA fortijump CVE-2024-47575https://github.com/watchtowrlabs/Fortijump-Exploit-CVE-2024-47575POC Details
21Nonehttps://github.com/expl0itsecurity/CVE-2024-47575POC Details
22FortiManager Unauthenticated Remote Code Execution (CVE-2024-47575)https://github.com/skyalliance/exploit-cve-2024-47575POC Details
23CVE-2024-47575是Fortinet的FortiManager和FortiManager Cloud产品中的一个严重漏洞,源于fgfmsd守护进程缺乏对关键功能的身份验证。https://github.com/XiaomingX/cve-2024-47575-pocPOC Details
24CVE-2024-47575是Fortinet的FortiManager和FortiManager Cloud产品中的一个严重漏洞,源于fgfmsd守护进程缺乏对关键功能的身份验证。https://github.com/XiaomingX/cve-2024-47575-expPOC Details
25CVE POC Exploithttps://github.com/Axi0n1ze/CVE-2024-47575-POCPOC Details
26CVE POC Exploithttps://github.com/Laonhearts/CVE-2024-47575-POCPOC Details
27CVE POC Exploithttps://github.com/Raygrants/CVE-2024-47575-POCPOC Details
28FortiManager Unauthenticated Remote Code Execution (CVE-2024-47575)https://github.com/SkyGodling/exploit-cve-2024-47575POC Details
29CVE POC Exploithttps://github.com/KaztoRay/CVE-2024-47575-POCPOC Details
30CVE POC Exploithttps://github.com/revanslbw/CVE-2024-47575-POCPOC Details
31PoC for CVE-2024-47575https://github.com/AnnnNix/CVE-2024-47575POC Details
32A missing authentication vulnerability in Fortinet FortiManager allows a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests to the fgfmd daemon. This vulnerability affects FortiManager versions 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.7, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.12, and all versions of 6.0. https://github.com/projectdiscovery/nuclei-templates/blob/main/code/cves/2024/CVE-2024-47575.yamlPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-47575

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2024-47575

No comments yet


Leave a comment