#VU72348 Improper Privilege Management in FortiOS - CVE-2022-38378
Published: February 17, 2023
FortiOS
Fortinet, Inc
Description
The vulnerability allows a remote user to escalate privileges on the device.
The vulnerability exists due to improper privilege management. A remote administrative user with access to the admin profile section (System subsection Administrator Users) can modify their own profile and upgrade their privileges to Read Write via CLI or GUI commands.