Improper Communication Channel Restriction in Fortinet FortiOS and Related Products
CVE-2024-26013
7.1HIGH
What is CVE-2024-26013?
An improper restriction of communication channel vulnerability in Fortinet products allows unauthenticated attackers positioned in a man-in-the-middle role to impersonate vital management devices, such as FortiCloud or FortiManager, by intercepting FGFM authentication requests between managed and management devices. This flaw affects multiple versions of FortiOS, FortiProxy, FortiManager, FortiAnalyzer, FortiVoice, and FortiWeb, potentially leading to unauthorized access and control over network configurations.
Affected Version(s)
FortiManager 7.4.0 <= 7.4.2
FortiManager 7.2.0 <= 7.2.4
FortiManager 7.0.0 <= 7.0.11