Impact
The vulnerability is an authentication bypass that allows an attacker to obtain improper access control by exploiting an alternate path or channel in Fortinet FortiManager. The weakness is classified as CWE-288, indicating inadequate authentication. If successfully abused, an attacker could log in to the management console or perform privileged operations without the proper credentials, potentially compromising the security of multiple managed devices.
Affected Systems
Fortinet FortiManager and FortiManager Cloud are affected. Versions 7.6.1, 7.4.3 through 7.4.5, and 7.2.5 through 7.2.9 of FortiManager, as well as the corresponding Cloud releases, are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity impact. EPSS data is not available, so the probability of exploitation is not quantified, but the vulnerability is not currently listed in CISA KEV, indicating no known widespread exploitation yet. The attack vector is not explicitly detailed in the advisory; based on the description it is inferred that the attacker would target an undocumented or alternate authentication endpoint or API. This path bypasses standard login controls, allowing unauthorized access that could lead to full administrative compromise of the fortified infrastructure.
OpenCVE Enrichment