# CVE-2024-47575

## Summary

- **CVE ID:** CVE-2024-47575
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:U/RC:C)
- **CWE:** CWE-306
- **Published:** Oct 23, 2024
- **Last Modified:** Oct 21, 2025

## Description

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.

## Affected Products

- Fortinet — FortiManager (7.6.0)
- Fortinet — FortiManager (7.4.0)
- Fortinet — FortiManager (7.2.0)
- Fortinet — FortiManager (7.0.0)
- Fortinet — FortiManager (6.4.0)
- Fortinet — FortiManager (6.2.0)

## References

- [CNA](https://fortiguard.fortinet.com/psirt/FG-IR-24-423)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-47575)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 95.07%
- **EPSS Percentile:** 99.9

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Oct 23, 2024
- **Due Date:** Nov 13, 2024

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._