logo

Fortinet FortiSwitch – Unverified Password Change Vulnerability

ID: f2178609-10f1-5d0b-8cb6-f1bd2f631a1a

STIX ID: report--f2178609-10f1-5d0b-8cb6-f1bd2f631a1a

Feed Name: Kudelski Security

Threat Score
78/100

Date Published: 2025-04-09

Date Updated: 2026-07-22

...
...

**CVE-2024-48887 — FortiSwitch unauthenticated password change (Critical, CVSS 9.3):** Fortinet disclosed a critical GUI vulnerability in multiple FortiSwitch versions that permits unauthenticated attackers to send crafted HTTP requests to change administrator passwords and execute commands on the device; Fortinet released patched versions and vendors/defenders are advised to apply updates, segment management interfaces, enable MFA, monitor logs, and deploy detection rules while no public PoC or confirmed exploitation in the wild has been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.