VYPR
Medium severity5.1NVD Advisory· Published Aug 13, 2024· Updated Jun 17, 2026

CVE-2024-36505

CVE-2024-36505

Description

An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system.

Affected products

3
  • Fortinet/Fortios3 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=6.4.13,<=6.4.15
    • (no CPE)range: 7.4.0-7.4.3, 7.2.5-7.2.7, 7.0.12-7.0.14, 6.4.x
    • (no CPE)range: 7.4.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.