A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile to super_admin via restoring modified configurations.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortios | Fortinet | * | 5.4.0 (including) |
Fortios | Fortinet | 5.6.0 (including) | 5.6.10 (including) |
Fortios | Fortinet | 6.0.0 (including) | 6.0.6 (including) |