Authorization Bypass in Fortinet FortiPortal Affects Multiple Versions
CVE-2024-45329

3.9LOW

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
10 June 2025

What is CVE-2024-45329?

In Fortinet FortiPortal, an authorization bypass vulnerability exists, allowing an authenticated attacker to manipulate user-controlled keys. This can lead to unauthorized access where sensitive device information may be disclosed through modified API requests. The issue affects several versions, necessitating immediate attention and patching to mitigate risks associated with exposure of critical information.

Affected Version(s)

FortiPortal 7.4.0

FortiPortal 7.2.0 <= 7.2.5

FortiPortal 7.0.0 <= 7.0.8

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-45329 : Authorization Bypass in Fortinet FortiPortal Affects Multiple Versions