FG-IR-25-006: Privilege escalation in GUI websocket module
An Improper Privilege Management vulnerability [CWE-269] affecting FortiOS, FortiProxy & FortiWeb may allow an authenticated attacker with at least read-only admin permissions to gain super-admin privileges via crafted requests to Node.js websocket module.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-25-006?
The severity of FG-IR-25-006 is classified as high due to its potential to allow an authenticated attacker to escalate privileges.
How do I fix FG-IR-25-006?
To fix FG-IR-25-006, upgrade FortiOS, FortiProxy, or FortiWeb to the latest version as specified in the advisory.
Which products are affected by FG-IR-25-006?
FG-IR-25-006 affects multiple versions of FortiOS, FortiProxy, and FortiWeb, specifically those below the patched versions.
Can an unauthenticated user exploit FG-IR-25-006?
No, FG-IR-25-006 requires the attacker to have at least read-only admin permissions to exploit the vulnerability.
What kind of attack is associated with FG-IR-25-006?
FG-IR-25-006 is associated with an improper privilege management attack that allows privilege escalation through crafted requests.