CVE-2023-45581: High severity fortinet forticlient ems cloud vulnerability
An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via crafted HTTP or HTTPS requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45581?
CVE-2023-45581 is considered a critical vulnerability due to its potential for improper privilege management allowing unauthorized global administrative actions.
How do I fix CVE-2023-45581?
To fix CVE-2023-45581, update Fortinet FortiClientEMS to version 7.2.3 or later, or to version 7.0.10 or earlier.
Which versions of Fortinet FortiClientEMS are affected by CVE-2023-45581?
CVE-2023-45581 affects Fortinet FortiClientEMS versions 7.2.0 through 7.2.2, and versions prior to 7.0.10.
What type of vulnerability is CVE-2023-45581 classified as?
CVE-2023-45581 is classified as an improper privilege management vulnerability, identified by CWE-269.
Who can be impacted by CVE-2023-45581?
Site administrators with Super Admin privileges may be impacted by CVE-2023-45581, allowing them to unintentionally perform global operations on other sites.