CVE-2024-48887

A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

Severity
Critical 9.3
CVSS 3.1
Exploited
Not listed
EPSS
0.148
96.4th percentile
Discovered by
Not disclosed
Published
Apr 8, 2025
Assigned by fortinet

Description

A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

Weakness: CWE-620

Affected products

Vendor Product Category Matched by
Fortinet FortiSwitch Routing & Switching cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiSwitch

Vendor remediation

Please upgrade to FortiSwitch version 7.6.1 or above Please upgrade to FortiSwitch version 7.4.5 or above Please upgrade to FortiSwitch version 7.2.9 or above Please upgrade to FortiSwitch version 7.0.11 or above Please upgrade to FortiSwitch version 6.4.15 or above