Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-23667

CVE-2024-23667: Fortinet FortiWebManager Auth Bypass Flaw

CVE-2024-23667 is an authentication bypass vulnerability in Fortinet FortiWebManager that allows attackers to execute unauthorized code via HTTP requests or CLI. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2024-23667 Overview

CVE-2024-23667 is an improper authorization vulnerability [CWE-285] affecting multiple versions of Fortinet FortiWebManager. The flaw allows an authenticated attacker to execute unauthorized code or commands through crafted HTTP requests or CLI operations. Fortinet published the advisory on June 3, 2024, tracking the issue as FG-IR-23-222.

The vulnerability impacts FortiWebManager 7.2.0, 7.0.0 through 7.0.4, 6.3.0, 6.2.3 through 6.2.4, and 6.0.2. Successful exploitation compromises the confidentiality, integrity, and availability of the management platform used to administer FortiWeb Web Application Firewall (WAF) deployments.

Critical Impact

An authenticated attacker with low privileges can execute unauthorized commands on the FortiWebManager appliance, potentially altering WAF policies across every managed device.

Affected Products

  • Fortinet FortiWebManager 7.2.0
  • Fortinet FortiWebManager 7.0.0 through 7.0.4
  • Fortinet FortiWebManager 6.3.0, 6.2.3 through 6.2.4, and 6.0.2

Discovery Timeline

  • 2024-06-03 - CVE-2024-23667 published to NVD and Fortinet PSIRT advisory FG-IR-23-222 released
  • 2026-07-08 - Last updated in NVD database

Technical Details for CVE-2024-23667

Vulnerability Analysis

CVE-2024-23667 is an improper authorization issue mapped to [CWE-285]. FortiWebManager fails to properly verify whether an authenticated user has sufficient privileges before executing certain operations. The attack surface spans both the HTTP management interface and the command-line interface (CLI), which broadens the exposure to any authenticated session on the appliance.

Because FortiWebManager centrally administers FortiWeb WAF instances, successful exploitation can cascade beyond the management plane. An attacker who executes unauthorized commands can modify WAF rules, disable protections, or pivot toward the web applications those WAFs defend. The vulnerability requires low privileges and no user interaction, and it is exploitable over the network.

Root Cause

The root cause is missing or inconsistent authorization checks on privileged operations exposed through HTTP endpoints and CLI commands. The application authenticates the session but does not re-validate whether the calling identity is entitled to perform the requested action. This gap allows low-privileged accounts to reach administrative functionality reserved for higher-privileged roles.

Attack Vector

Exploitation requires network access to the FortiWebManager management interface and valid, low-privileged credentials. An attacker sends crafted HTTP requests to restricted management endpoints or invokes CLI commands that should be blocked for the current role. Because the vulnerability affects the management plane, exposure of FortiWebManager to untrusted networks materially increases risk. See the Fortinet PSIRT Advisory FG-IR-23-222 for vendor-provided technical details.

Detection Methods for CVE-2024-23667

Indicators of Compromise

  • Unexpected configuration changes to WAF policies, administrative accounts, or managed device inventories on FortiWebManager.
  • Authenticated HTTP requests from low-privileged accounts targeting administrative API paths or CLI operations they should not access.
  • CLI command executions recorded in audit logs that fall outside the calling user's assigned role.

Detection Strategies

  • Correlate FortiWebManager audit logs with role assignments to identify privileged actions performed by non-administrative accounts.
  • Alert on HTTP requests to management endpoints returning success codes for users whose role should trigger denial.
  • Baseline normal administrative behavior per account and flag deviations such as bulk policy edits or new admin creation.

Monitoring Recommendations

  • Forward FortiWebManager syslog and CLI audit logs to a SIEM or centralized data lake for retention and correlation.
  • Monitor for authentication events immediately followed by privileged configuration changes from the same session.
  • Track outbound changes pushed from FortiWebManager to managed FortiWeb devices for unauthorized policy modifications.

How to Mitigate CVE-2024-23667

Immediate Actions Required

  • Upgrade FortiWebManager to a fixed release as specified in Fortinet PSIRT Advisory FG-IR-23-222.
  • Restrict management interface access to trusted administrative networks and jump hosts only.
  • Audit all FortiWebManager user accounts, remove unused accounts, and rotate credentials for accounts with recent activity.

Patch Information

Fortinet released fixed versions of FortiWebManager in the FG-IR-23-222 advisory. Administrators should consult the Fortinet PSIRT Advisory FG-IR-23-222 to identify the exact upgrade path for each affected branch, including 7.2.x, 7.0.x, 6.3.x, 6.2.x, and 6.0.x deployments. Apply the upgrade following Fortinet's documented procedure and validate configuration integrity after the upgrade.

Workarounds

  • If immediate patching is not feasible, place FortiWebManager behind a management VPN and block all untrusted network access to HTTP and CLI services.
  • Enforce least privilege by reviewing role assignments and removing administrative permissions from accounts that do not require them.
  • Enable multi-factor authentication for all FortiWebManager administrative accounts to raise the cost of credential-based access.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.