Fortinet FortiManager Improper Access Control Vulnerability in FortiGate via Valid Credentials

Vulnerability

A vulnerability allowing improper access control has been identified in Fortinet FortiManager versions 6.4.12 through 7.4.0. This vulnerability arises from an operation on a resource after its expiration or release, which can allow an attacker to gain unauthorized access to FortiGate using valid credentials. Specifically, an admin account deleted through FortiManager may still be able to log into FortiGate.

Impact

Exploitation of this vulnerability could lead to unauthorized access to FortiGate devices via valid credentials, allowing for potential administrative actions or changes on the device.

Remediation

Users can upgrade Fortinet FortiManager to version 7.4.1 or above, 7.2.4 or above, or 6.4.13 or above, depending on their current version. Fortinet FortiManager 7.6 is not affected by this vulnerability. As a workaround, admin accounts intended to be deleted should be removed directly from the FortiGate.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
5.0
exploitability
4.6
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.