FG-IR-23-459: Privilege escalation from low privilege administrator
An improper access control vulnerability [CWE-284] in FortiExtender authentication component may allow a remote authenticated attacker to create users with elevated privileges via a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-459?
The severity of FG-IR-23-459 is classified based on the potential impact of improper access control vulnerabilities in FortiExtender.
How do I fix FG-IR-23-459?
To fix FG-IR-23-459, update your FortiExtender to version 7.4.3 or higher, 7.2.5 or higher, or 7.0.5 or higher depending on your current version.
What products are impacted by FG-IR-23-459?
FG-IR-23-459 affects multiple versions of FortiExtender, specifically versions from 7.0.0 to 7.4.2.
What type of vulnerability is FG-IR-23-459?
FG-IR-23-459 is an improper access control vulnerability, identified as CWE-284.
Who is affected by FG-IR-23-459?
Organizations using FortiExtender versions that are within the affected ranges may be impacted by FG-IR-23-459.