QID 44102
Date Published: 2023-10-12
QID 44102: FortiOS Privilege Escalation Vulnerability (FG-IR-23-318)
An improper authorization vulnerability in FortiOS's WEB UI component may allow an authenticated attacker belonging to the prof-admin profile to perform elevated actions..
Affected Versions:
FortiOS version 7.2.0 through 7.2.4
FortiOS version 7.0.0 through 7.0.11
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Successful exploit may allow an authenticated attacker belonging to the prof-admin profile to perform elevated actions.
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-23-318
Vendor References
- FG-IR-23-318 -
www.fortiguard.com/psirt/FG-IR-23-318
CVEs related to QID 44102
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-318 |
|