CVE-2024-23663
published 2024-07-09CVE-2024-23663: An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to…
PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.64%
46.4th percentile
An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to create users with elevated privileges via a crafted HTTP request.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiextender | — | — |
| fortinet | fortiextender | 7.0.0 – 7.0.4 | — |
| fortinet | fortiextender | 7.2.0 – 7.2.4 | — |
| fortinet | fortiextender | 7.4.0 – 7.4.2 | — |
| fortinet | fortiextender_firmware | — | — |
| fortinet | fortiextender_firmware | 4.1.1 – 4.1.9 | — |
| fortinet | fortiextender_firmware | 4.2.0 – 4.2.6 | — |
| fortinet | fortiextender_firmware | 7.0.0 – 7.0.4 | — |
| fortinet | fortiextender_firmware | 7.2.0 – 7.2.4 | — |
| fortinet | fortiextender_firmware | 7.4.0 – 7.4.2 | — |
| fortinet | fortiextenderfirmware | — | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r293-2ppv-632r: An improper access control in Fortinet FortiExtender 4
ghsa_unreviewed·2024-07-09
CVE-2024-23663 [HIGH] CWE-284 GHSA-r293-2ppv-632r: An improper access control in Fortinet FortiExtender 4
An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to create users with elevated privileges via a crafted HTTP request.
Fortinet
Privilege escalation from low privilege administrator
vendor_fortinet·2024-07-09·CVSS 8.8
CVE-2024-23663 [HIGH] CWE-284 Privilege escalation from low privilege administrator
FG-IR-23-459: Privilege escalation from low privilege administrator
An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to create users with elevated privileges via a crafted HTTP request.
CVEs: CVE-2024-23663
CWEs: CWE-284
CVSS: 8.8 (high)
Affected products: FortiExtender, FortiExtenderfirmware, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-07-09
Published