
CVE-2024-47575 (FortiJump) Explained: FortiManager Auth Bypass
CVE-2024-47575 is a CVSS 9.8 missing authentication vulnerability in Fortinet FortiManager (FortiManager Cloud also affected) that allows an unauthenticated remote attacker to execute arbitrary code or commands via specially crafted requests to the FGFM (FortiGate to FortiManager) daemon. Dubbed 'FortiJump' by Mandiant. Exploited as a zero-day by UNC5820, a suspected Chinese state-sponsored actor, targeting managed service providers and enterprise FortiManager deployments. CISA added it to the KEV catalog on October 23, 2024.
