FG-IR-23-318: Improper authorization via prof-admin profile
An improper authorization vulnerability [CWE-285] in FortiOS's WEB UI component may allow an authenticated attacker belonging to the prof-admin profile to perform elevated actions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-318?
The severity of FG-IR-23-318 is classified as critical due to the potential for unauthorized elevated actions by an authenticated attacker.
How do I fix FG-IR-23-318?
To fix FG-IR-23-318, update FortiOS to the latest version that includes the patch addressing this improper authorization vulnerability.
Who is affected by FG-IR-23-318?
FG-IR-23-318 affects users of FortiOS, specifically those with access to the WEB UI component and holding the prof-admin profile.
What can an attacker do with FG-IR-23-318?
An attacker exploiting FG-IR-23-318 can perform elevated actions that are normally restricted, posing a serious security risk.
Is there a workaround for FG-IR-23-318?
Currently, there are no recommended workarounds for FG-IR-23-318, and the best mitigation is to apply the appropriate software update.