FG-IR-24-127: Multiple privilege escalation
An improper privilege management vulnerability [CWE 269] in FortiManager and FortiAnalyzer may allow a local attacker to escalate their privileges by abusing incorrect filesystem permissions
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-127?
The FG-IR-24-127 vulnerability has been assigned a significant severity level due to its potential for privilege escalation.
How do I fix FG-IR-24-127?
To remediate the FG-IR-24-127 vulnerability, upgrade FortiManager and FortiAnalyzer to version 7.4.4 or 7.2.6 or the recommended versions based on the specific product.
Which products are affected by FG-IR-24-127?
The FG-IR-24-127 vulnerability affects FortiAnalyzer and FortiManager across several versions.
What type of vulnerability is FG-IR-24-127?
FG-IR-24-127 is categorized as an improper privilege management vulnerability, specifically identified by CWE 269.
Can a remote attacker exploit FG-IR-24-127?
No, FG-IR-24-127 requires local access for exploitation by an attacker.