Impact
Fortinet appliances that have FortiCloud SSO enabled can be compromised via an Authentication Bypass Using an Alternate Path or Channel vulnerability (CWE‑288). An attacker who owns a FortiCloud account and has a device registered to that account can authenticate to any other device of another account that also uses FortiCloud SSO, thereby gaining full administrative control over that target device. This bypass removes the normal account and device authentication checks and can be used to move laterally to additional network assets.
Affected Systems
Affected products include FortiAnalyzer (versions 7.0.0–7.0.15, 7.2.0–7.2.11, 7.4.0–7.4.9, 7.6.0–7.6.5), FortiManager (versions 7.0.0–7.0.15, 7.2.0–7.2.11, 7.4.0–7.4.9, 7.6.0–7.6.5), FortiNAC‑F (7.6.3–7.6.5), FortiOS (7.0.0–7.0.18, 7.2.0–7.2.12, 7.4.0–7.4.10, 7.6.0–7.6.5), FortiProxy (7.0.0–7.0.22, 7.2.0–7.2.15, 7.4.0–7.4.12, 7.6.0–7.6.4), FortiWeb (7.4.0–7.4.11, 7.6.0–7.6.6, 8.0.0–8.0.3), FortiSwitchManager (up to 7.2.9 and 7.0.8 for older releases).
Risk and Exploitability
The vulnerability has a CVSS score of 9.4 and an EPSS score of 86%, and it is listed in the CISA KEV catalog, confirming that active exploits exist. Exploitation can be performed remotely by an attacker who has a FortiCloud account with at least one registered device; the attacker exploits the FortiCloud SSO channel to authenticate as an administrator on another device, after which lateral movement to other assets is possible.
OpenCVE Enrichment