Home Fortinet CVE-2024-27784
Back to Fortinet

CVE-2024-27784

FortiAIOps - API Endpoint

Fortinet CVSS 8.8 Updated March 16, 2026

Executive Risk Summary

"A vulnerability in Fortinet FortiAIOps 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log files, potentially exposing sensitive data. This vulnerability is classified as a Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability."

Operational Audit Arsenal

Target Type API Endpoint
Target Asset FortiAIOps API
Standard Path Global Firmware

Manual Verification Required

This is a non-Windows asset (Fortinet). Use the target asset details above to verify your version against vendor advisories.

Patch Impact Forecast

Reboot Required Likely

Moderate

Internal Work Notes

FortiAIOps API vulnerability (CVE-2024-27784) - potential sensitive information exposure, requires patching and verification of version

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Scope of Impact

Fortinet Fortiaiops (Version 2.0.0)

Original NVD Description

"Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log files."

Related Fortinet Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.