← back
CVE-2024-35277

CVE-2024-35277

CVSS 8.4 HIGHEPSS 0.7%CWE-306
A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the managed devices by sending specifically crafted packets
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:F/RL:U/RC:C
Affected products
Fortinet · FortiManager

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →