QID 44102

Date Published: 2023-10-12

QID 44102: FortiOS Privilege Escalation Vulnerability (FG-IR-23-318)

An improper authorization vulnerability in FortiOS's WEB UI component may allow an authenticated attacker belonging to the prof-admin profile to perform elevated actions..

Affected Versions:
FortiOS version 7.2.0 through 7.2.4
FortiOS version 7.0.0 through 7.0.11

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.

Successful exploit may allow an authenticated attacker belonging to the prof-admin profile to perform elevated actions.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-23-318

    Vendor References

    CVEs related to QID 44102

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-23-318 URL Logo www.fortiguard.com/psirt/FG-IR-23-318