FG-IR-24-302: Permission escalation due to an Improper Privilege Management
An incorrect privilege assignment vulnerability [CWE-266] in the FortiOS security fabric may allow an authenticated admin whose access profile has the Security Fabric write permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-302?
FG-IR-24-302 is classified as a critical vulnerability due to the potential for privilege escalation.
How do I fix FG-IR-24-302?
To fix FG-IR-24-302, update FortiOS to a version that contains the remediation, such as 7.6.1 or newer.
What products are affected by FG-IR-24-302?
FG-IR-24-302 affects multiple versions of FortiOS, specifically versions prior to 7.6.1, 7.4.5, 7.2.10, and 7.0.16.
Can I exploit FG-IR-24-302 remotely?
Yes, FG-IR-24-302 can be exploited remotely if an authenticated admin with specific permissions is targeted.
What is the impact of FG-IR-24-302?
Exploiting FG-IR-24-302 may allow an authenticated admin to gain super-admin privileges, compromising system security.