CVE-2024-47575: FortiManager Unauthenticated RCE (FortiJump)
What is FortiJump?
A missing authentication vulnerability in FortiManager's FGFM (FortiGate to FortiManager) daemon. Unauthenticated attackers can execute arbitrary code and commands via specially crafted requests, dubbed "FortiJump" by researchers.
Impact & Exploitation
Exploited as a zero-day since June 2024. Over 50 organizations compromised before disclosure. Enables complete control of FortiManager and all managed FortiGate firewalls.
How Precogs AI Detects FortiManager Unauthenticated RCE (FortiJump)
Precogs AI Binary SAST analyzes FortiManager firmware for missing authentication in management protocols, detecting vulnerabilities in network management infrastructure.