#VU103835 Incorrect privilege assignment in FortiOS - CVE-2024-40591
Published: February 11, 2025
FortiOS
Fortinet, Inc
Description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to incorrect privilege management in the FortiOS security fabric. A remote user can with Security Fabric permission can escalate privileges to super-admin by connecting the target FortiGate to a malicious upstream FortiGate they control.