CVE-2024-40591: Permission escalation due to an Improper Privilege Management
An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.
Other sources
An incorrect privilege assignment vulnerability [CWE-266] in the FortiOS security fabric may allow an authenticated admin whose access profile has the Security Fabric write permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40591?
CVE-2024-40591 is classified as a high severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2024-40591?
To address CVE-2024-40591, update Fortinet FortiOS to version 7.4.5 or later, 7.3.0 or later, or 7.0.15 or later.
Who is affected by CVE-2024-40591?
CVE-2024-40591 affects users of Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9, and versions before 7.0.15.
What type of vulnerability is CVE-2024-40591?
CVE-2024-40591 is an incorrect privilege assignment vulnerability, allowing unauthorized privilege escalation.
What is the impact of exploiting CVE-2024-40591?
Exploitation of CVE-2024-40591 allows an authenticated admin to escalate their privileges to super-admin status, potentially compromising system security.