PT-2024-5555 · Fortinet · Fortiextender

Published

2024-01-19

·

Updated

2024-09-09

·

CVE-2024-23663

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Fortinet FortiExtender versions 4.1.1 through 4.1.9 Fortinet FortiExtender versions 4.2.0 through 4.2.6 Fortinet FortiExtender version 5.3.2 Fortinet FortiExtender versions 7.0.0 through 7.0.4 Fortinet FortiExtender versions 7.2.0 through 7.2.4 Fortinet FortiExtender versions 7.4.0 through 7.4.2
Description The issue is related to improper access control in the Fortinet FortiExtender system, allowing an attacker to create users with elevated privileges via a crafted HTTP request. This can be exploited by sending a specially formed HTTP request, enabling the attacker to bypass security restrictions and elevate their privileges.
Recommendations For Fortinet FortiExtender versions 4.1.1 through 4.1.9, upgrade to a secure version to mitigate the risk. For Fortinet FortiExtender versions 4.2.0 through 4.2.6, upgrade to a secure version to mitigate the risk. For Fortinet FortiExtender version 5.3.2, upgrade to a secure version to mitigate the risk. For Fortinet FortiExtender versions 7.0.0 through 7.0.4, upgrade to a secure version to mitigate the risk. For Fortinet FortiExtender versions 7.2.0 through 7.2.4, upgrade to a secure version to mitigate the risk. For Fortinet FortiExtender versions 7.4.0 through 7.4.2, upgrade to a secure version to mitigate the risk. As a temporary workaround, consider restricting access to the HTTP endpoint to minimize the risk of exploitation.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-06234
CVE-2024-23663

Affected Products

Fortiextender