CVE-2024-54020 LOW

CVE-2024-54020

Vendor Fortinet
Product FortiManager
Weakness CWE-862 · Missing authorization
Published May 28, 2025
Last update May 28, 2025

CVSS base score

2.1/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C

What the vulnerability does

01Description

A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allow an authenticated attacker to overwrite global threat feeds via crafted update requests.

Key dates

02Disclosure timeline

May 28, 2025 CVE published
May 28, 2025 Record updated

Related vulnerabilities

04Related CVE