CVE-2024-48886 describes a critical weak authentication vulnerability in multiple Fortinet products, including FortiOS, FortiProxy, FortiManager, FortiManager Cloud, and FortiAnalyzer Cloud. This flaw, rated 9.8 CVSS, allows an unauthenticated attacker to execute arbitrary code or commands through a brute-force attack due to low attack complexity and no user interaction required. While the EPSS score indicates a low probability of exploitation compared to other CVEs, and there is no known active exploitation or public exploit code, its high severity warrants immediate attention. There is currently no significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.4.1, < 7.4.4CPE matchmatch criteria | cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* | ||
>= 7.6.0, < 7.6.2CPE matchmatch criteria | cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* | ||
>= 7.4.1, < 7.4.4CPE matchmatch criteria | cpe:2.3:a:fortinet:fortianalyzer_cloud:*:*:*:*:*:*:*:* | ||
>= 7.4.1, < 7.4.4CPE matchmatch criteria | cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* | ||
>= 7.6.0, < 7.6.2CPE matchmatch criteria | cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.