First published: Fri Oct 25 2024(Updated: )
An improper authorization vulnerability [CWE-285] in FortiOS's WEB UI component may allow an authenticated attacker belonging to the prof-admin profile to perform elevated actions.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine | >=7.2.0<=7.2.4 | |
Fortinet FortiOS IPS Engine | >=7.0.0<=7.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of FG-IR-23-318 is classified as critical due to the potential for unauthorized elevated actions by an authenticated attacker.
To fix FG-IR-23-318, update FortiOS to the latest version that includes the patch addressing this improper authorization vulnerability.
FG-IR-23-318 affects users of FortiOS, specifically those with access to the WEB UI component and holding the prof-admin profile.
An attacker exploiting FG-IR-23-318 can perform elevated actions that are normally restricted, posing a serious security risk.
Currently, there are no recommended workarounds for FG-IR-23-318, and the best mitigation is to apply the appropriate software update.