A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.
History

Thu, 22 Aug 2024 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Fortinet
Fortinet fortianalyzer
Fortinet fortimanager
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortianalyzer
Fortinet fortimanager

Tue, 13 Aug 2024 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 16:00:00 +0000

Type Values Removed Values Added
Description A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.
Weaknesses CWE-620
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N/E:P/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2024-08-13T15:51:57.495Z

Updated: 2024-08-13T17:48:37.502Z

Reserved: 2024-01-02T10:15:00.526Z

Link: CVE-2024-21757

cve-icon Vulnrichment

Updated: 2024-08-13T17:48:25.375Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-13T16:15:08.637

Modified: 2024-08-22T14:34:54.550

Link: CVE-2024-21757

cve-icon Redhat

No data.