First published: Tue Oct 10 2023(Updated: )
An improper authorization vulnerability [CWE-285] in FortiOS's WEB UI component may allow an authenticated attacker belonging to the prof-admin profile to perform elevated actions.
Credit: psirt@fortinet.com psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | >=7.0.0<=7.0.11 | |
Fortinet FortiOS | >=7.2.0<=7.2.4 | |
Fortinet FortiOS | >=7.2.0<=7.2.4 | |
Fortinet FortiOS | >=7.0.0<=7.0.11 |
Please upgrade to FortiOS version 7.4.0 or above Please upgrade to FortiOS version 7.2.5 or above Please upgrade to FortiOS version 7.0.12 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41841 is an improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 that allows an attacker belonging to the prof-admin profile to perform elevated actions.
CVE-2023-41841 has a severity rating of 8.1, which is considered high.
CVE-2023-41841 affects Fortinet FortiOS versions 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4.
An attacker belonging to the prof-admin profile can exploit CVE-2023-41841 to perform elevated actions.
You can find more information about CVE-2023-41841 on the FortiGuard website: [https://fortiguard.com/psirt/FG-IR-23-318](https://fortiguard.com/psirt/FG-IR-23-318)