QID 44145
QID 44145: FortiOS Privilege Escalation Vulnerability (FG-IR-17-053)
A privilege escalation vulnerability in FortiOS may allow admin users to elevate their profile to super_admin, via restoring modified configurations.
Affected Versions:
FortiOS 6.0.0 to 6.0.6
FortiOS 5.6.0 to 5.6.10
FortiOS 5.4 all versions and below.
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Successful exploit may allows admin users to elevate their profile to super_admin via restoring modified configurations
Solution
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-17-053
Vendor References
- FG-IR-17-053 -
www.fortiguard.com/psirt/FG-IR-17-053
CVEs related to QID 44145
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-17-053 |
|