CVE-2017-17544

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
09/04/2019
Last modified:
28/08/2020

Description

A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile to super_admin via restoring modified configurations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 5.4.0 (including)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 5.6.0 (including) 5.6.10 (including)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.6 (including)