CVE-2024-40591
published 2025-02-11CVE-2024-40591: An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows…
PriorityP342high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.60%
44.5th percentile
An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortigate | — | — |
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.4.0 < 6.4.16 | 6.4.16 |
| fortinet | fortios | 6.4.0 – 6.4.15 | — |
| fortinet | fortios | >= 7.0.0 < 7.0.16 | 7.0.16 |
| fortinet | fortios | 7.0.0 – 7.0.15 | — |
| fortinet | fortios | >= 7.2.0 < 7.2.10 | 7.2.10 |
| fortinet | fortios | 7.2.0 – 7.2.9 | — |
| fortinet | fortios | >= 7.4.0 < 7.4.5 | 7.4.5 |
| fortinet | fortios | 7.4.0 – 7.4.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hmpg-p67j-959p: An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7
ghsa_unreviewed·2025-02-11
CVE-2024-40591 [HIGH] CWE-266 GHSA-hmpg-p67j-959p: An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7
An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.
Fortinet
Permission escalation due to an Improper Privilege Management
vendor_fortinet·2025-02-11·CVSS 8.8
CVE-2024-40591 [HIGH] CWE-266 Permission escalation due to an Improper Privilege Management
FG-IR-24-302: Permission escalation due to an Improper Privilege Management
An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.
CVEs: CVE-2024-40591
CWEs: CWE-266
CVSS: 8.8 (high)
Affected products: FortiGate, FortiOS, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-11
Published