Critical Vulnerability Alert: Hackers Can Remotely Hijack FortiSwitch Admin Passwords


# Critical Vulnerability in Fortinet FortiSwitch Devices Patched

Fortinet has released urgent security patches addressing a critical vulnerability in FortiSwitch devices that allows remote attackers to change administrator passwords without authentication. The flaw, discovered internally by Daniel Rozeboom of the FortiSwitch web UI development team, has been assigned CVE-2024-48887 and carries a severe 9.8/10 severity rating.

## Vulnerability Details

The security flaw involves an unverified password change vulnerability in the FortiSwitch GUI. Unauthenticated attackers can exploit this weakness by sending specially crafted requests to the set_password endpoint, allowing them to modify administrator credentials without requiring user interaction or complex attack methods.

## Affected Versions and Patches

The vulnerability impacts multiple FortiSwitch versions from 6.4.0 through 7.6.0. Fortinet has released the following patches:

| Version | Affected Range | Recommended Action |
|———|—————-|——————-|
| FortiSwitch 7.6 | 7.6.0 | Upgrade to 7.6.1 or above |
| FortiSwitch 7.4 | 7.4.0 – 7.4.4 | Upgrade to 7.4.5 or above |
| FortiSwitch 7.2 | 7.2.0 – 7.2.8 | Upgrade to 7.2.9 or above |
| FortiSwitch 7.0 | 7.0.0 – 7.0.10 | Upgrade to 7.0.11 or above |
| FortiSwitch 6.4 | 6.4.0 – 6.4.14 | Upgrade to 6.4.15 or above |

## Temporary Workaround

For organizations unable to immediately apply the security updates, Fortinet recommends:
– Disabling ‘HTTP/HTTPS Access’ from administrative interfaces
– Restricting access to vulnerable FortiSwitch devices to trusted hosts only

## Additional Vulnerabilities Patched

In the same update, Fortinet also addressed:
– An OS command injection vulnerability (CVE-2024-54024) in FortiIsolator
– Flaws in FortiOS, FortiProxy, FortiManager, FortiAnalyzer, FortiVoice, and FortiWeb (CVE-2024-26013 and CVE-2024-50565) that could be exploited in man-in-the-middle attacks

## History of Exploitation

Fortinet vulnerabilities have frequently been targeted in the wild, with several exploited as zero-days before patches were available. Recent examples include:
– A zero-day in FortiClient Windows VPN client used by Chinese hackers with the DeepData post-exploitation toolkit
– The “FortiJump” vulnerability (CVE-2024-47575) in FortiManager, exploited to breach over 50 servers since June 2024
– Two additional vulnerabilities (CVE-2024-55591 and CVE-2025-24472) exploited in ransomware attacks earlier this year

Organizations using affected FortiSwitch devices are strongly encouraged to apply the patches immediately.

Share This Article