First published: Tue Feb 11 2025(Updated: )
An incorrect privilege assignment vulnerability [CWE-266] in the FortiOS security fabric may allow an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS IPS Engine | =. | |
Fortinet FortiOS IPS Engine | >=7.4.0<=7.4.4 | |
Fortinet FortiOS IPS Engine | >=7.2.0<=7.2.9 | |
Fortinet FortiOS IPS Engine | >=7.0.0<=7.0.15 | |
Fortinet FortiOS IPS Engine | >=6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
FG-IR-24-302 is classified as a critical vulnerability due to the potential for privilege escalation.
To fix FG-IR-24-302, update FortiOS to a version that contains the remediation, such as 7.6.1 or newer.
FG-IR-24-302 affects multiple versions of FortiOS, specifically versions prior to 7.6.1, 7.4.5, 7.2.10, and 7.0.16.
Yes, FG-IR-24-302 can be exploited remotely if an authenticated admin with specific permissions is targeted.
Exploiting FG-IR-24-302 may allow an authenticated admin to gain super-admin privileges, compromising system security.