Appsecure logo

CVE-2024-40591: High Vulnerability in Fortinet FortiOS

A high-severity privilege escalation vulnerability has been identified in Fortinet FortiOS. This flaw allows authenticated administrators to escalate their privileges. Immediate action is recommended to mitigate risks.

HIGHCVSS 8.8 · Published February 11, 2025

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9, and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targeted FortiGate to a malicious upstream FortiGate they control. The CVSS score for this vulnerability is 8.8, categorizing it as high severity.

Risk to organizations includes potential unauthorized access to critical system functionalities and data loss. Attackers may leverage this vulnerability to gain elevated privileges, compromising the integrity and availability of systems. Organizations should prioritize patching immediately to mitigate this risk.

Currently, there are no known exploits or public proof of concepts available for this CVE. However, the high exploitability rating indicates that the potential for exploitation is significant, which underscores the urgency for defenders to act.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.