Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54606 | A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allow an authenticated attacker to overwrite global threat feeds via crafted update requests. |
Solution
Please upgrade to FortiManager version 7.4.0 or above Please upgrade to FortiManager version 7.2.2 or above Please upgrade to FortiManager version 7.0.8 or above
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-023 |
|
Thu, 05 Jun 2025 01:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* |
Thu, 29 May 2025 00:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 May 2025 17:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allow an authenticated attacker to overwrite global threat feeds via crafted update requests. | |
| First Time appeared |
Fortinet
Fortinet fortimanager |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:o:fortinet:fortimanager:7.0.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortimanager:7.0.1:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortimanager:7.0.2:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortimanager:7.0.3:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortimanager:7.0.4:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortimanager:7.0.5:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortimanager:7.0.6:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortimanager:7.0.7:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortimanager:7.2.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortimanager:7.2.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet fortimanager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-05-28T14:21:37.049Z
Reserved: 2024-11-27T15:20:39.890Z
Link: CVE-2024-54020
Updated: 2025-05-28T14:21:31.548Z
Status : Analyzed
Published: 2025-05-28T08:15:20.043
Modified: 2025-06-04T14:34:54.323
Link: CVE-2024-54020
No data.
OpenCVE Enrichment
No data.
EUVD