An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated actions via crafted HTTP or HTTPS requests.
2024-01-10T18:15:46.030
2024-11-21T08:25:31.227
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiproxy | 7.4.0 | Yes |
Application | fortinet | fortiproxy | 7.4.1 | Yes |
Operating System | fortinet | fortios | 7.2.5 | Yes |
Operating System | fortinet | fortios | 7.4.0 | Yes |
Operating System | fortinet | fortios | 7.4.1 | Yes |