An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, FortiProxy 7.4.0 through 7.4.2, FortiProxy 7.2.0 through 7.2.8, FortiProxy 7.0.0 through 7.0.15, FortiSwitchManager 7.2.0 through 7.2.3, FortiSwitchManager 7.0.0 through 7.0.3 allows an unauthenticated attacker to seize control of a managed device via crafted FGFM requests, if the device is managed by a FortiManager, and if the attacker knows that FortiManager's serial number.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-042 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
20 Apr 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, FortiProxy 7.4.0 through 7.4.2, FortiProxy 7.2.0 through 7.2.8, FortiProxy 7.0.0 through 7.0.15, FortiSwitchManager 7.2.0 through 7.2.3, FortiSwitchManager 7.0.0 through 7.0.3 allows an unauthenticated attacker to seize control of a managed device via crafted FGFM requests, if the device is managed by a FortiManager, and if the attacker knows that FortiManager's serial number. |
14 Aug 2025, 01:13
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-042 - Vendor Advisory | |
| First Time |
Fortinet fortipam
Fortinet Fortinet fortiproxy Fortinet fortios Fortinet fortiswitchmanager |
13 Aug 2025, 17:33
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
12 Aug 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-08-12 19:15
Updated : 2026-04-20 09:16
NVD link : CVE-2024-26009
Mitre link : CVE-2024-26009
CVE.ORG link : CVE-2024-26009
JSON object : View
Products Affected
fortinet
- fortiswitchmanager
- fortiproxy
- fortipam
- fortios
CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel
