CVE-2024-48887
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request
Severity
Critical 9.3
CVSS 3.1
Exploited
Not listed
EPSS
0.148
96.4th percentile
Discovered by
Not disclosed
Published
Apr 8, 2025
Assigned by fortinet
Description
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request
Weakness: CWE-620
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSwitch | Routing & Switching | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiSwitch
Vendor remediation
Please upgrade to FortiSwitch version 7.6.1 or above Please upgrade to FortiSwitch version 7.4.5 or above Please upgrade to FortiSwitch version 7.2.9 or above Please upgrade to FortiSwitch version 7.0.11 or above Please upgrade to FortiSwitch version 6.4.15 or above