FortiManager and FortiAnalyzer
CVE-2024-47571: Operation on a resource after expiration or release in FortiManager
An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| FortiManager 7.4 | 7.4.1 or later |
| FortiManager 7.2 | 7.2.4 or later |
| FortiManager 7.0.7 to 7.0.8 | 7.0.9 or later |
| FortiManager 6.4 | 6.4.13 or later |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.