ID

VAR-202504-1837


CVE

CVE-2024-48887


TITLE

Fortinet FortiSwitch Authorization Issue Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-12795

DESCRIPTION

A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request. Fortinet FortiSwitch is a network switch management tool from Fortinet, an American company. Fortinet FortiSwitch has an authorization issue vulnerability, which stems from unauthenticated password changes. Attackers can exploit this vulnerability to cause the administrator password to be tampered with

Trust: 1.44

sources: NVD: CVE-2024-48887 // CNVD: CNVD-2025-12795

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-12795

AFFECTED PRODUCTS

vendor:fortinetmodel:fortiswitchscope:eqversion:7.6.0

Trust: 0.6

vendor:fortinetmodel:fortiswitchscope:gteversion:7.4.0,<=7.4.4

Trust: 0.6

vendor:fortinetmodel:fortiswitchscope:gteversion:7.2.0,<=7.2.8

Trust: 0.6

vendor:fortinetmodel:fortiswitchscope:gteversion:7.0.0,<=7.0.10

Trust: 0.6

vendor:fortinetmodel:fortiswitchscope:gteversion:6.4.0,<=6.4.14

Trust: 0.6

sources: CNVD: CNVD-2025-12795

CVSS

SEVERITY

CVSSV2

CVSSV3

psirt@fortinet.com: CVE-2024-48887
value: CRITICAL

Trust: 1.0

CNVD: CNVD-2025-12795
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-12795
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

psirt@fortinet.com: CVE-2024-48887
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-12795 // NVD: CVE-2024-48887

PROBLEMTYPE DATA

problemtype:CWE-620

Trust: 1.0

sources: NVD: CVE-2024-48887

PATCH

title:Patch for Fortinet FortiSwitch Authorization Issue Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/698701

Trust: 0.6

sources: CNVD: CNVD-2025-12795

EXTERNAL IDS

db:NVDid:CVE-2024-48887

Trust: 1.6

db:CNVDid:CNVD-2025-12795

Trust: 0.6

sources: CNVD: CNVD-2025-12795 // NVD: CVE-2024-48887

REFERENCES

url:https://fortiguard.fortinet.com/psirt/fg-ir-24-435

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-48887

Trust: 0.6

sources: CNVD: CNVD-2025-12795 // NVD: CVE-2024-48887

SOURCES

db:CNVDid:CNVD-2025-12795
db:NVDid:CVE-2024-48887

LAST UPDATE DATE

2025-06-19T23:32:11.548000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-12795date:2025-06-18T00:00:00
db:NVDid:CVE-2024-48887date:2025-04-08T18:13:53.347

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-12795date:2025-06-17T00:00:00
db:NVDid:CVE-2024-48887date:2025-04-08T17:15:34.440