CVE-2024-47575
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 throu...
Affects 2 products across 1 vendor.
Software does not perform any authentication for functionality that requires a verified identity.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
CVE-2024-47575 affects multiple versions of FortiManager, including cloud and on-premises deployments, due to a missing authentication for critical functions. This vulnerability allows an attacker to execute arbitrary code or commands via specially crafted requests, posing a significant risk to the security and integrity of affected systems.
BSID: BS-2024-GLOBAL-269011-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2024-47575?
What is the CVSS score for CVE-2024-47575?
Is CVE-2024-47575 actively exploited?
How do I remediate CVE-2024-47575?
What systems are affected by CVE-2024-47575?
What NERC-CIP standard applies to CVE-2024-47575?
What IEC 62443 requirement maps to CVE-2024-47575?
| CVE ID | CVE-2024-47575 |
|---|---|
| BSID | BS-2024-GLOBAL-269011-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2024-10-23 |
| Last Modified | 2025-10-24 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.
Source: NIST NVD / MITRE CVE Database
The vulnerability can be exploited remotely without authentication, requiring no user interaction. An attacker can send specially crafted requests to the affected FortiManager instances, leading to the execution of arbitrary code or commands. This could result in complete system compromise, data exfiltration, or disruption of services.
Exploitation Likelihood: CRITICAL
| CISA KEV | ● Active Exploitation Confirmed (added 2024-10-23) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict network segmentation and access controls to limit exposure to untrusted networks. Ensure that only authorized personnel have access to the management interfaces of affected FortiManager devices.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 by allowing unauthorized access to critical functions, which could lead to the compromise of electronic security perimeters and control systems.
This CVE maps to SR 7.6 because it involves a lack of proper authentication mechanisms, which is essential for protecting against unauthorized access and ensuring the integrity and availability of industrial control systems.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | a5027271df97f3cfa58bb3c964fa1d5f8e9a5bf111fa5ed401904a67696e1a087f5e1ef0727280614d8dd4a9b65d6e36925a3ef071fbd245c2b37938835ad548 |
This Vulnerability Is Being Actively Exploited
CVE-2024-47575 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.
Start Free KEV Monitoring →