QID 43917

Date Published: 2022-10-18

QID 43917: FortiOS Privilege Escalation Vulnerability (FG-IR-20-131)

An improper access control vulnerability [CWE-284] in FortiOS and FortiProxy autod daemon may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script and auto-script features.

Affected Products:
FortiOS version 7.0.0
FortiOS versions 6.4.6 and below
FortiOS versions 6.2.9 and below
FortiOS versions 6.0.12 and below
FortiOS versions 5.6.x
FortiOS-6K7K version 6.4.2
FortiOS-6K7K version 6.2.6 and below

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Vulnerable version of FortiOS may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script and auto-script features.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-20-131

    Vendor References

    CVEs related to QID 43917

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-20-131 URL Logo www.fortiguard.com/psirt/FG-IR-20-131