Fortinet FortiSwitch – Unverified Password Change Vulnerability
ID: f2178609-10f1-5d0b-8cb6-f1bd2f631a1a
STIX ID: report--f2178609-10f1-5d0b-8cb6-f1bd2f631a1a
Feed Name: Kudelski Security
**CVE-2024-48887 — FortiSwitch unauthenticated password change (Critical, CVSS 9.3):** Fortinet disclosed a critical GUI vulnerability in multiple FortiSwitch versions that permits unauthenticated attackers to send crafted HTTP requests to change administrator passwords and execute commands on the device; Fortinet released patched versions and vendors/defenders are advised to apply updates, segment management interfaces, enable MFA, monitor logs, and deploy detection rules while no public PoC or confirmed exploitation in the wild has been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
