TT-CSIRT – 439.09.04.25. Security Update – FortiSwitch Vulnerability

TT-CSIRT – 439.09.04.25. Security Update – FortiSwitch Vulnerability

Please be advised that Fortinet has released a security update to address a critical vulnerability (CVE-2024-48887) found in the FortiSwitch GUI. This vulnerability could enable a remote unauthenticated attacker to alter admin passwords through a specifically designed request.

Impact

  • Exploitation could lead to full system compromise
  • Weakness Enumeration: CWE-620 – Unverified Password Change
  • Type: Privilege escalation

Affected Versions

VersionAffectedSolution
FortiSwitch 7.67.6.0Upgrade to 7.6.1 or above
FortiSwitch 7.47.4.0 through 7.4.4Upgrade to 7.4.5 or above
FortiSwitch 7.27.2.0 through 7.2.8Upgrade to 7.2.9 or above
FortiSwitch 7.07.0.0 through 7.0.10Upgrade to 7.0.11 or above
FortiSwitch 6.46.4.0 through 6.4.14Upgrade to 6.4.15 or above

Solution: Update affected build to the latest version as seen above:

Workaround

  • Disable HTTP/HTTPS access from administrative interfaces.
  • Configure trusted hosts to restrict which hosts can connect to the system.

Reference:

If you have any queries, comments or require assistance, please feel free to contact TT-CSIRT via contacts@ttcsirt.gov.tt