CVE-2024-40591

EUVD-2025-4981
An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
fortinetfortios
6.4.0 ≤
𝑥
< 6.4.16
fortinetfortios
7.0.0 ≤
𝑥
< 7.0.16
fortinetfortios
7.2.0 ≤
𝑥
< 7.2.10
fortinetfortios
7.4.0 ≤
𝑥
< 7.4.5
fortinetfortios
7.6.0
𝑥
= Vulnerable software versions