Логотип exploitDog
bind:CVE-2024-40591
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-40591

Количество 3

Количество 3

nvd логотип

CVE-2024-40591

12 месяцев назад

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-hmpg-p67j-959p

12 месяцев назад

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2025-01611

12 месяцев назад

Уязвимость операционных систем FortiOS, связанная с некорректным присваиванием привилегий, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-40591

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.

CVSS3: 8.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-hmpg-p67j-959p

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.

CVSS3: 8.8
0%
Низкий
12 месяцев назад
fstec логотип
BDU:2025-01611

Уязвимость операционных систем FortiOS, связанная с некорректным присваиванием привилегий, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.8
0%
Низкий
12 месяцев назад

Уязвимостей на страницу