FortiManager Password Modification Vulnerability
CVE-2024-21757
What is CVE-2024-21757?
The vulnerability identifies a significant security issue in Fortinet's FortiManager and FortiAnalyzer products where an unverified password change can occur. Specifically, versions 7.0.0 through 7.0.10, 7.2.0 through 7.2.4, and 7.4.0 through 7.4.1 are susceptible. An attacker can exploit this flaw to modify administrative passwords using the device configuration backup. This vulnerability underscores the necessity for implementing robust security measures and caution during backup operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FortiAnalyzer 7.4.0 <= 7.4.1
FortiAnalyzer 7.2.0 <= 7.2.4
FortiAnalyzer 7.0.0 <= 7.0.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved