FG-IR-23-315: Improper authorization for HA requests
An improper privilege management vulnerability [CWE-269] in a FortiOS & FortiProxy HA cluster may allow an authenticated attacker to perform elevated actions over the web administrative interface via crafted HTTP or HTTPS requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-315?
The severity of FG-IR-23-315 is classified as high due to its potential for improper privilege management.
How do I fix FG-IR-23-315?
To fix FG-IR-23-315, update FortiOS to version 7.4.2 or higher for affected 7.4.x versions and to 7.2.6 for 7.2.x versions.
What are the affected products for FG-IR-23-315?
FG-IR-23-315 affects FortiOS versions 7.4.0 to 7.4.1 and FortiProxy versions 7.4.0 to 7.4.1.
Who can exploit FG-IR-23-315?
An authenticated attacker can exploit FG-IR-23-315 to perform elevated actions through the web administrative interface.
What type of vulnerability is FG-IR-23-315?
FG-IR-23-315 is an improper privilege management vulnerability categorized under CWE-269.