An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-302 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
17 Jul 2025, 20:12
Type | Values Removed | Values Added |
---|---|---|
First Time |
Fortinet
Fortinet fortios |
|
CPE | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:* |
|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-302 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
11 Feb 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-11 17:15
Updated : 2025-07-17 20:12
NVD link : CVE-2024-40591
Mitre link : CVE-2024-40591
JSON object : View
Products Affected
fortinet
- fortios
CWE
CWE-266
Incorrect Privilege Assignment