A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-23-467 |
|
History
Thu, 22 Aug 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortianalyzer Fortinet fortimanager |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet fortianalyzer Fortinet fortimanager |
Tue, 13 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Aug 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup. | |
| Weaknesses | CWE-620 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published: 2024-08-13T15:51:57.495Z
Updated: 2024-08-13T17:48:37.502Z
Reserved: 2024-01-02T10:15:00.526Z
Link: CVE-2024-21757
Updated: 2024-08-13T17:48:25.375Z
Status : Analyzed
Published: 2024-08-13T16:15:08.637
Modified: 2024-08-22T14:34:54.550
Link: CVE-2024-21757
No data.