CVE-2023-26205: High severity Fortinet FortiADC vulnerability
An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to superadmin via a specific crafted configuration of fabric automation CLI script.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2023-26205.
What is the severity of CVE-2023-26205?
The severity of CVE-2023-26205 is high with a score of 8.1.
Which software versions are affected by this vulnerability?
FortiADC automation feature versions 7.1.0 through 7.1.2, 7.0, 6.2, and 6.1 are affected.
How can an attacker exploit this vulnerability?
An authenticated low-privileged attacker can escalate their privileges to super_admin via a specifically crafted configuration of fabric authentication users and groups.
Is there a patch available for this vulnerability?
It is recommended to update to the latest version of FortiADC that addresses this vulnerability.