Vulnerability Details CVE-2023-44250
An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated actions via crafted HTTP or HTTPS requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 27.6%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2023-44250
-
cpe:2.3:a:fortinet:fortiproxy:7.4.0
-
cpe:2.3:a:fortinet:fortiproxy:7.4.1
-
cpe:2.3:o:fortinet:fortios:7.2.5
-
cpe:2.3:o:fortinet:fortios:7.4.0
-
cpe:2.3:o:fortinet:fortios:7.4.1