Fortinet has released security updates for a critical vulnerability in FortiSwitch devices , which could allow an attacker to change admin passwords remotely.

The vulnerability is tracked as CVE-2024-48887 (9.8/10) and was discovered by Daniel Rozeboom from the FortiSwitch web UI development team.
See also: Fortinet: Hackers exploit vulnerability in FortiOS and FortiProxy
Unauthorized attackers can exploit this flaw in FortiSwitch in low-sophistication attacks that do not require user interaction.
Fortinet says that threat actors can change credentials using a specially crafted request sent through the set_password endpoint.
“A password change [CWE-620] in the FortiSwitch GUI could allow an unauthorized remote attacker to modify admin passwords via a specially crafted request,” Fortinet says.
See also: Windows Remote Desktop vulnerability allows RCE execution
The bug affects multiple versions: from FortiSwitch 6.4.0 to FortiSwitch 7.6.0. The company fixed in FortiSwitch versions 6.4.15, 7.0.11, 7.2.9, 7.4.5, and 7.6.1.
If one cannot immediately apply the security updates, they should disable "HTTP/HTTPS Access" from administrative interfaces and restrict access to vulnerable FortiSwitch devices (only to trusted computers).

Beyond applying updates and disabling “HTTP/HTTPS Access,” maintaining a robust security posture is crucial to defending against vulnerability exploits. This includes integrating multiple layers of defense, including intrusion detection and prevention systems (IDPS), network segmentation, and continuous monitoring for suspicious activity.
See also: Vulnerabilities fixed in Ivanti, VMware, Zoom products
Additionally, investing in employee training to recognize phishing attempts and other social engineering attacks can further reduce the likelihood of systems being compromised.
By prioritizing proactive defense strategies alongside rapid remediation, organizations can significantly enhance their resilience against such threats and protect their infrastructure from advanced cyber attacks.
Source: www.bleepingcomputer.com
