A vulnerability has been identified in Fortinet FortiManager installations. The vulnerability could allow for unauthenticated Remote Code Execution (RCE). The vulnerability (CVE-2024-47575) has a Critical CVSSv3.1 score of 9.8 out of 10.
The vulnerability lies in the FortiGate to FortiManager Protocol (FGFM) and has been dubbed FortiJump by security researchers. Due to a missing authentication vulnerability, a remote unauthenticated attacker is able to execute arbitrary code or commands on the FortiManager platform via specially crafted requests. The only requirement for exploitation is for an attacker to possess a valid Fortinet device certificate, which can be acquired from any enrolled Fortinet device.
Publicly disclosed by Fortinet on October 23, limited customer disclosure and patching was initiated about a week earlier. While recent, there are already reports of in - the - wild exploitation. Prompt patching of devices with the functionality is very strongly encouraged. Fortinet has shared a precise list of vulnerable versions, as well as a number of alternative workarounds besides full patching, found below.