A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3 allows attacker to execute unauthorized code or commands via a brute-force attack.
CVSS Details
- CVSS 3.1 Base Score: 9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortianalyzer | — | Upgrade FortiAnalyzer to 7.6.2Upgrade FortiAnalyzer to 7.4.4 | Feb 6, 2025 | Jan 14, 2025 |
| Fortinet Fortimanager | — | Upgrade FortiManager to 7.4.4Upgrade FortiManager to 7.6.2 | Feb 6, 2025 | Jan 14, 2025 |
| Fortinet Fortiproxy | — | Upgrade FortiProxy to 7.2.11Upgrade FortiProxy to 7.4.5Upgrade FortiProxy to 2.0.15Upgrade to the latest version of FortiProxyUpgrade FortiProxy to 7.0.18 | Sep 30, 2026 | Jan 14, 2025 |
| Fortios | — | Upgrade to the latest version of FortiOSUpgrade FortiOS to 7.4.5Upgrade FortiOS to 7.0.16Upgrade FortiOS to 7.2.9 | Feb 6, 2025 | Jan 14, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub