An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-302 |
Configurations
No configuration.
History
11 Feb 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-11 17:15
Updated : 2025-02-11 17:15
NVD link : CVE-2024-40591
Mitre link : CVE-2024-40591
CVE.ORG link : CVE-2024-40591
JSON object : View
Products Affected
No product.
CWE
CWE-266
Incorrect Privilege Assignment