CVE-2023-41841: Improper authorization via prof-admin profile
An improper authorization vulnerability [CWE-285] in FortiOS's WEB UI component may allow an authenticated attacker belonging to the prof-admin profile to perform elevated actions.
Other sources
An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile to perform elevated actions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-41841?
CVE-2023-41841 is an improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 that allows an attacker belonging to the prof-admin profile to perform elevated actions.
How severe is CVE-2023-41841?
CVE-2023-41841 has a severity rating of 8.1, which is considered high.
Which software versions are affected by CVE-2023-41841?
CVE-2023-41841 affects Fortinet FortiOS versions 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4.
How can an attacker exploit CVE-2023-41841?
An attacker belonging to the prof-admin profile can exploit CVE-2023-41841 to perform elevated actions.
Where can I find more information about CVE-2023-41841?
You can find more information about CVE-2023-41841 on the FortiGuard website: [https://fortiguard.com/psirt/FG-IR-23-318](https://fortiguard.com/psirt/FG-IR-23-318)