An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-302 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
17 Jul 2025, 20:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-302 - Vendor Advisory | |
CPE | cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
|
First Time |
Fortinet fortios
Fortinet |
|
Summary |
|
11 Feb 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-11 17:15
Updated : 2025-07-17 20:12
NVD link : CVE-2024-40591
Mitre link : CVE-2024-40591
CVE.ORG link : CVE-2024-40591
JSON object : View
Products Affected
fortinet
- fortios
CWE
CWE-266
Incorrect Privilege Assignment