PT-2024-5555 · Fortinet · Fortiextender
Published
2024-01-19
·
Updated
2024-09-09
·
CVE-2024-23663
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiExtender versions 4.1.1 through 4.1.9
Fortinet FortiExtender versions 4.2.0 through 4.2.6
Fortinet FortiExtender version 5.3.2
Fortinet FortiExtender versions 7.0.0 through 7.0.4
Fortinet FortiExtender versions 7.2.0 through 7.2.4
Fortinet FortiExtender versions 7.4.0 through 7.4.2
Description
The issue is related to improper access control in the Fortinet FortiExtender system, allowing an attacker to create users with elevated privileges via a crafted HTTP request. This can be exploited by sending a specially formed HTTP request, enabling the attacker to bypass security restrictions and elevate their privileges.
Recommendations
For Fortinet FortiExtender versions 4.1.1 through 4.1.9, upgrade to a secure version to mitigate the risk.
For Fortinet FortiExtender versions 4.2.0 through 4.2.6, upgrade to a secure version to mitigate the risk.
For Fortinet FortiExtender version 5.3.2, upgrade to a secure version to mitigate the risk.
For Fortinet FortiExtender versions 7.0.0 through 7.0.4, upgrade to a secure version to mitigate the risk.
For Fortinet FortiExtender versions 7.2.0 through 7.2.4, upgrade to a secure version to mitigate the risk.
For Fortinet FortiExtender versions 7.4.0 through 7.4.2, upgrade to a secure version to mitigate the risk.
As a temporary workaround, consider restricting access to the HTTP endpoint to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiextender