{"id":6103,"date":"2025-08-13T10:03:36","date_gmt":"2025-08-13T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/13\/fortios-fortiproxy-and-fortipam-auth-bypass-vulnerability-allows-attackers-to-gain-full-control\/"},"modified":"2025-08-13T10:03:36","modified_gmt":"2025-08-13T10:03:36","slug":"fortios-fortiproxy-and-fortipam-auth-bypass-vulnerability-allows-attackers-to-gain-full-control","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/13\/fortios-fortiproxy-and-fortipam-auth-bypass-vulnerability-allows-attackers-to-gain-full-control\/","title":{"rendered":"FortiOS, FortiProxy, and FortiPAM Auth Bypass Vulnerability Allows Attackers to Gain Full Control"},"content":{"rendered":"<p>    FortiOS, FortiProxy, and FortiPAM Auth Bypass Vulnerability Allows Attackers to Gain Full Control<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A high-severity authentication bypass vulnerability affecting multiple Fortinet security products, including FortiOS, <a href=\"https:\/\/cybersecuritynews.com\/133k-vulnerable-fortios-fortiproxy\/\">Fo<\/a><a href=\"https:\/\/cybersecuritynews.com\/133k-vulnerable-fortios-fortiproxy\/\" target=\"_blank\" rel=\"noreferrer noopener\">r<\/a><a href=\"https:\/\/cybersecuritynews.com\/133k-vulnerable-fortios-fortiproxy\/\">tiProxy<\/a>, and FortiPAM systems.\u00a0<\/p>\n<p>The flaw, designated as CVE-2024-26009 with a CVSS score of 7.9, enables unauthenticated attackers to seize complete control of managed devices through exploitation of the FortiGate-to-FortiManager (FGFM) communication protocol.<\/p>\n<pre class=\"wp-block-preformatted\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">Key Takeaways<\/mark><\/strong><br>1. CVE-2024-26009 allows authentication bypass in Fortinet products.<br>2. Attackers gain complete administrative access to managed devices.<br>3. Upgrade affected FortiOS, FortiProxy, and FortiPAM versions immediately.<\/pre>\n<h2 class=\"wp-block-heading\" id=\"h-authentication-bypass-vulnerability\"><strong>Authentication Bypass Vulnerability<\/strong><\/h2>\n<p>The vulnerability stems from an <a href=\"https:\/\/cybersecuritynews.com\/tag\/authentication-bypass\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication bypass<\/a> using an alternate path or channel, classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel).\u00a0<\/p>\n<p>Attackers can exploit this weakness by crafting malicious FGFM requests to target devices managed by FortiManager systems.\u00a0<\/p>\n<p>The critical prerequisite for successful exploitation is the attacker\u2019s knowledge of the target FortiManager\u2019s serial number, which serves as a key authentication component in the compromised protocol implementation.<\/p>\n<p>The FGFM protocol, designed for secure communication between FortiGate devices and central management systems, contains a fundamental authentication flaw that allows unauthorized command execution.\u00a0<\/p>\n<p>This vulnerability affects legacy versions across multiple product lines, with FortiOS versions 6.0 through 6.4.15 and 6.2.0 through 6.2.16 being particularly vulnerable.\u00a0<\/p>\n<p>FortiProxy installations running versions 7.0.0 through 7.0.15, 7.2.0 through 7.2.8, and 7.4.0 through 7.4.2 are also at risk.<\/p>\n<p>The potential impact is severe, as successful exploitation grants attackers the ability to execute unauthorized code or commands on compromised systems, effectively providing administrative-level access to critical network infrastructure components.<\/p>\n<p>Security researchers from Fortinet\u2019s internal Product Security team, led by Th\u00e9o Leleu, <a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-24-042\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">discovered this vulnerability<\/a> during routine security assessments.\u00a0<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Risk Factors<\/strong><\/td>\n<td><strong>Details<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Affected Products<\/td>\n<td>FortiOS 6.0-6.4.15, FortiProxy 7.0-7.4.2, FortiPAM 1.0-1.2, FortiSwitchManager 7.0-7.2.3<\/td>\n<\/tr>\n<tr>\n<td>Impact<\/td>\n<td>Execute unauthorized code or commands, full administrative control<\/td>\n<\/tr>\n<tr>\n<td>Exploit Prerequisites<\/td>\n<td>Device managed by FortiManager + Knowledge of FortiManager\u2019s serial number<\/td>\n<\/tr>\n<tr>\n<td>CVSS 3.1 Score<\/td>\n<td>7.9 (High Severity)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-mitigations\"><strong>Mitigations<\/strong><\/h2>\n<p>Organizations using affected versions must prioritize immediate patching. Fortinet recommends upgrading FortiOS 6.4 installations to version 6.4.16 or higher, while FortiOS 6.2 users should upgrade to 6.2.17 or above.<\/p>\n<p>\u00a0FortiProxy users must update to versions 7.0.16, 7.2.9, or 7.4.3, depending on their current installation.\u00a0<\/p>\n<p>Legacy FortiPAM versions 1.0, 1.1, and 1.2 require complete migration to newer releases, as patches are not available for these obsolete versions.<\/p>\n<p>Network administrators should utilize Fortinet\u2019s upgrade tool available at their documentation portal to ensure proper upgrade paths and minimize potential service disruptions during the patching process.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/fortinet-authentication-bypass\/\">FortiOS, FortiProxy, and FortiPAM Auth Bypass Vulnerability Allows Attackers to Gain Full Control<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/fortinet-authentication-bypass\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>FortiOS, FortiProxy, and FortiPAM Auth Bypass Vulnerability Allows Attackers to Gain Full Control A high-severity authentication bypass vulnerability affecting multiple Fortinet security products, including FortiOS, FortiProxy, and FortiPAM systems.\u00a0 The flaw, designated as CVE-2024-26009 with a CVSS score of 7.9, enables unauthenticated attackers to seize complete control of managed devices through exploitation of the FortiGate-to-FortiManager [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,416,131,648],"tags":[130],"class_list":["post-6103","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerabilities","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6103"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6103"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6103\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6103"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6103"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6103"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}