Article Details

Scrape Timestamp (UTC): 2025-04-08 17:57:59.667

Source: https://thehackernews.com/2025/04/fortinet-urges-fortiswitch-upgrades-to.html

Original Article Text

Click to Toggle View

Fortinet Urges FortiSwitch Upgrades to Patch Critical Admin Password Change Flaw. Fortinet has released security updates to address a critical security flaw impacting FortiSwitch that could permit an attacker to make unauthorized password changes. The vulnerability, tracked as CVE-2024-48887, carries a CVSS score of 9.3 out of a maximum of 10.0. "An unverified password change vulnerability [CWE-620] in FortiSwitch GUI may allow a remote unauthenticated attacker to modify admin passwords via a specially crafted request," Fortinet said in an advisory released today. The shortcoming impacts the following versions - The network security company said the security hole was internally discovered and reported by Daniel Rozeboom of the FortiSwitch web UI development team. As workarounds, Fortinet recommends disabling HTTP/HTTPS access from administrative interfaces and restricting access to the system to only trusted hosts. While there is no evidence that the vulnerability has been exploited, a number of security flaws affecting Fortinet products have been weaponized by threat actors, making it essential that users move quickly to apply the patches.

Daily Brief Summary

MALWARE // Fortinet Releases Patch for Critical FortiSwitch Vulnerability

Fortinet has issued updates to fix a critical flaw in FortiSwitch, identified as CVE-2024-48887, with a CVSS score of 9.3.

The vulnerability allows unauthorized remote attackers to change admin passwords through a specifically crafted request in the GUI.

The security issue was detected internally by a member of the FortiSwitch web UI development team, Daniel Rozeboom.

Affected users are advised to disable HTTP/HTTPS access to administrative interfaces and limit system access to trusted hosts.

Although there have been no reported exploitations of this specific flaw, previous vulnerabilities in Fortinet products have been leveraged by cybercriminals.

Implementing the newly released security patches promptly is crucial for maintaining the security integrity of the network.