---
id: CVE-2024-23670
title: >-
  An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager
  7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through
  6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or
  commands …
summary: >-
  An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager
  7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through
  6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or
  commands …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-285
vendor: fortinet
product: fortiwebmanager
affected:
  - 'fortiwebmanager >= 6.2.3, < 6.2.5'
  - 'fortiwebmanager >= 7.0.0, < 7.0.5'
  - fortiwebmanager = 6.0.2
  - fortiwebmanager = 6.3.0
  - fortiwebmanager = 7.2.0
patched:
  - fortiwebmanager 7.0.5
published: '2024-06-03'
updated: '2026-07-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-23670'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-23-222'
    label: psirt@fortinet.com
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-23-222'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00443
epssPercentile: 0.3793
ingestedAt: '2026-07-08T14:51:15.592Z'
---

## Overview

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

## Affected

- `fortiwebmanager >= 6.2.3, < 6.2.5`
- `fortiwebmanager >= 7.0.0, < 7.0.5`
- `fortiwebmanager = 6.0.2`
- `fortiwebmanager = 6.3.0`
- `fortiwebmanager = 7.2.0`

## Remediation

Upgrade past the affected range:

- `fortiwebmanager 7.0.5`
