📦 Fortimanager

by Fortinet

🔍 What is Fortimanager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-24858

CRITICAL CVSS 9.8 Jan 27, 2026

This authentication bypass vulnerability allows attackers with a FortiCloud account and registered device to log into other organizations' Fortinet devices when FortiCloud SSO authentication is enable...

CVE-2023-25610

CRITICAL CVSS 9.8 Mar 24, 2025

This critical vulnerability allows remote unauthenticated attackers to execute arbitrary code or commands on affected Fortinet devices via crafted requests to the administrative interface. It affects ...

CVE-2024-48886

CRITICAL CVSS 9.0 Jan 14, 2025

This vulnerability allows attackers to bypass weak authentication mechanisms in multiple Fortinet products via brute-force attacks, potentially leading to unauthorized command execution. Affected syst...

CVE-2024-47575

CRITICAL CVSS 9.8 Oct 23, 2024

This critical vulnerability in FortiManager allows unauthenticated attackers to execute arbitrary code or commands via specially crafted requests. It affects multiple versions of FortiManager and Fort...

CVE-2024-46662

HIGH CVSS 8.8 Mar 14, 2025

This command injection vulnerability in Fortinet FortiManager allows attackers to execute arbitrary commands with elevated privileges by sending specially crafted packets. Affected systems include For...

CVE-2024-40584

HIGH CVSS 7.2 Feb 11, 2025

This OS command injection vulnerability in Fortinet FortiAnalyzer and FortiManager products allows authenticated privileged attackers to execute arbitrary commands via crafted HTTP/HTTPS requests. Att...

CVE-2024-50563

HIGH CVSS 7.3 Jan 16, 2025

This vulnerability allows attackers to perform brute-force attacks against Fortinet management platforms due to weak authentication mechanisms. Successful exploitation could lead to unauthorized code ...

CVE-2024-45331

HIGH CVSS 7.3 Jan 16, 2025

This CVE describes an incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer, FortiManager, and FortiAnalyzer Cloud products. Attackers can execute specific shell commands to escalate ...

CVE-2024-50566

HIGH CVSS 7.2 Jan 14, 2025

This CVE describes an OS command injection vulnerability in Fortinet FortiManager and FortiManager Cloud products. Authenticated remote attackers can execute arbitrary commands via crafted FGFM reques...

CVE-2024-47571

HIGH CVSS 8.1 Jan 14, 2025

This vulnerability in Fortinet FortiManager allows attackers with valid credentials to gain improper access to FortiGate devices through an operation on a resource after expiration or release. It affe...

CVE-2024-35277

HIGH CVSS 8.6 Jan 14, 2025

This vulnerability allows unauthenticated attackers to access configuration data of managed devices by sending specially crafted packets to Fortinet FortiPortal and FortiManager systems. It affects or...

CVE-2024-36512

HIGH CVSS 7.2 Jan 14, 2025

This path traversal vulnerability in Fortinet FortiManager and FortiAnalyzer allows attackers to execute arbitrary code or commands via specially crafted HTTP/HTTPS requests. Affected organizations in...

CVE-2024-35273

HIGH CVSS 7.2 Jan 14, 2025

This vulnerability allows attackers to execute arbitrary code with elevated privileges on Fortinet FortiManager and FortiAnalyzer systems through specially crafted HTTP requests. It affects organizati...

CVE-2021-32589

HIGH CVSS 8.1 Dec 19, 2024

A use-after-free vulnerability in FortiManager and FortiAnalyzer's fgfmsd daemon allows remote unauthenticated attackers to execute arbitrary code as root by sending specially crafted requests to the ...

CVE-2023-36554

HIGH CVSS 8.1 Mar 12, 2024

This vulnerability allows attackers to execute arbitrary code or commands on Fortinet FortiManager devices through specially crafted HTTP requests due to improper access control. Affected organization...

CVE-2023-25607

HIGH CVSS 7.8 Oct 10, 2023

This CVE describes an OS command injection vulnerability in Fortinet management interfaces that allows authenticated users with READ permissions to execute arbitrary shell commands. The vulnerability ...

CVE-2023-22642

HIGH CVSS 7.5 Apr 11, 2023

This CVE describes an improper certificate validation vulnerability in FortiAnalyzer and FortiManager devices that allows remote unauthenticated attackers to perform man-in-the-middle attacks on commu...

CVE-2021-32603

HIGH CVSS 8.8 Aug 5, 2021

This is a server-side request forgery (SSRF) vulnerability in FortiManager and FortiAnalyser GUI that allows authenticated attackers to make unauthorized requests from the vulnerable system. Attackers...

CVE-2024-40593

MEDIUM CVSS 6.0 Dec 11, 2025

This vulnerability allows authenticated administrators on affected Fortinet devices to retrieve certificate private keys via the admin shell. This affects FortiAnalyzer, FortiManager, FortiOS, and For...

CVE-2024-52964

MEDIUM CVSS 5.5 Aug 12, 2025

This path traversal vulnerability in Fortinet FortiManager and FortiManager Cloud allows authenticated remote attackers to overwrite arbitrary files via crafted FGFM requests. Attackers could potentia...

CVE-2024-52962

MEDIUM CVSS 5.3 Apr 8, 2025

An unauthenticated remote attacker can inject malicious content into FortiAnalyzer and FortiManager logs via crafted login requests. This log pollution vulnerability affects all supported versions of ...

CVE-2024-32123

MEDIUM CVSS 6.7 Mar 11, 2025

This CVE describes an OS command injection vulnerability in Fortinet FortiManager and FortiAnalyzer products. Attackers can execute arbitrary commands on affected systems by sending crafted CLI reques...

CVE-2024-33504

MEDIUM CVSS 4.1 Feb 11, 2025

This vulnerability in FortiManager allows attackers with JSON API access permissions to decrypt sensitive data due to hard-coded cryptographic keys. It affects FortiManager versions 7.6.0-7.6.1, 7.4.0...

CVE-2024-36508

MEDIUM CVSS 6.0 Feb 11, 2025

This path traversal vulnerability in Fortinet FortiManager and FortiAnalyzer allows authenticated admin users with diagnose privileges to delete arbitrary files on the system. It affects specific vers...

CVE-2024-32115

MEDIUM CVSS 5.5 Jan 14, 2025

A relative path traversal vulnerability in Fortinet FortiManager allows privileged attackers to delete files from the underlying filesystem via crafted HTTP/HTTPS requests. This affects FortiManager v...

CVE-2024-33503

MEDIUM CVSS 6.7 Jan 14, 2025

This vulnerability allows attackers to escalate privileges on Fortinet FortiManager and FortiAnalyzer systems by executing specific shell commands. Affected users are those running vulnerable versions...

CVE-2024-35275

MEDIUM CVSS 6.6 Jan 14, 2025

This SQL injection vulnerability in Fortinet FortiAnalyzer and FortiManager allows attackers to execute arbitrary SQL commands through specially crafted HTTP requests, potentially leading to privilege...

CVE-2024-32118

MEDIUM CVSS 6.7 Nov 12, 2024

This CVE describes OS command injection vulnerabilities in Fortinet FortiManager and FortiAnalyzer products. Authenticated privileged attackers can execute arbitrary commands via crafted CLI requests,...

CVE-2024-32116

MEDIUM CVSS 5.1 Nov 12, 2024

This vulnerability allows privileged attackers to delete arbitrary files from the underlying filesystem via crafted CLI requests in affected Fortinet products. It affects FortiManager, FortiAnalyzer, ...

CVE-2024-26011

MEDIUM CVSS 5.3 Nov 12, 2024

This vulnerability allows unauthenticated attackers to execute arbitrary code or commands on affected Fortinet devices by sending specially crafted packets. It affects multiple Fortinet products inclu...

CVE-2023-44255

MEDIUM CVSS 4.1 Nov 12, 2024

This vulnerability allows authenticated administrators with read permissions in Fortinet FortiManager, FortiAnalyzer, and FortiAnalyzer-BigData to access event logs from administrative domains (adoms)...

CVE-2023-44254

MEDIUM CVSS 5.0 Sep 10, 2024

This vulnerability allows remote attackers with low-privilege accounts to bypass authorization controls and read sensitive data via crafted HTTP requests. It affects FortiAnalyzer and FortiManager net...