Skip to content
Threat Feed
medium advisory

Fortinet FortiManager Security Feature Bypass Vulnerability

A remote, unauthenticated attacker can exploit a vulnerability in Fortinet FortiManager to bypass security controls, necessitating immediate monitoring of management interface traffic.

CVE search metadata

CVE search record: CVE-2024-47575. Severity: critical. CVSS: 9.8. EPSS: 94.95%. KEV: no. Product: FortiManager. Brief: Fortinet FortiManager Security Feature Bypass Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-08-fortimanager-bypass/

The German Federal Office for Information Security (BSI) has released a security advisory regarding a vulnerability in Fortinet FortiManager. This security feature bypass flaw allows a remote, unauthenticated attacker to circumvent established security measures. Given that FortiManager acts as a centralized management plane for Fortinet environments, this vulnerability carries significant risk for enterprise infrastructure. Defenders should monitor for unauthorized access attempts or anomalous behavior originating from network segments with access to the FortiManager management interface. Organizations using affected versions are urged to consult the official Fortinet PSIRT advisories to identify vulnerable firmware releases and implement necessary updates immediately.

Impact

Successful exploitation of this vulnerability allows an unauthorized actor to bypass security mechanisms on the FortiManager appliance. This could lead to a loss of centralized oversight, unauthorized configuration changes, or further compromise of the managed network perimeter. The extent of potential damage includes full control over the management plane, which would enable the attacker to modify firewall rules, push malicious policies to downstream FortiGate devices, or exfiltrate sensitive configuration data.

Recommendation

Prioritize patching for Fortinet FortiManager across all environments, specifically targeting the version ranges identified by Fortinet PSIRT associated with CVE-2024-47575. Restrict access to FortiManager management interfaces (typically ports 443, 8443, and 541) to known administrative subnets at the network level until patches are verified. Review logs for unexpected authentication requests or anomalies in administrative traffic patterns directed at the FortiManager web-based or CLI management endpoints.


Immediate actions

Patch FortiManager for CVE-2024-47575

IT Operations 24h

Mitigations

Restrict management interface access via network ACLs

immediate IT Operations

CVE-2024-47575