CVE-2024-40591

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profi

Severity
High 8
CVSS 3.1
Exploited
Not listed
EPSS
0.006
48.4th percentile
Discovered by
Vendor
Vendor advisory field
Published
Feb 11, 2025
Assigned by fortinet

Description

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.

Weakness: CWE-266

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiOS

Credit

Internally discovered and reported by Justin Lum from Fortinet's R&D team.

Vendor remediation

Please upgrade to FortiOS version 7.6.1 or above Please upgrade to FortiOS version 7.4.5 or above Please upgrade to FortiOS version 7.2.10 or above Please upgrade to FortiOS version 7.0.16 or above

Something wrong here?