A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile to super_admin via restoring modified configurations.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://fortiguard.com/advisory/FG-IR-17-053 | vendor advisory |
http://www.securityfocus.com/bid/107839 | vdb entry third party advisory |