CVE-2024-35277

A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the managed devices by sending specifically crafted packets
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
fortinetCNA
8.4 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:F/RL:U/RC:C
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
VendorProductVersion
fortinetfortimanager
6.4.0 ≤
𝑥
< 6.4.15
fortinetfortimanager
7.0.0 ≤
𝑥
< 7.0.13
fortinetfortimanager
7.2.0 ≤
𝑥
< 7.2.6
fortinetfortimanager
7.4.0 ≤
𝑥
< 7.4.3
fortinetfortimanager_cloud
7.0.1 ≤
𝑥
< 7.0.13
fortinetfortimanager_cloud
7.2.1 ≤
𝑥
< 7.2.7
fortinetfortimanager_cloud
7.4.1 ≤
𝑥
< 7.4.3
𝑥
= Vulnerable software versions