8.8
CVSSv3

CVE-2024-40591

CVSSv4: NA | CVSSv3: 8.8 | CVSSv2: NA | VMScore: 980 | EPSS: 0.00054 | KEV: Not Included
Published: 11/02/2025 Updated: 11/02/2025

Vulnerability Summary

Privilege Escalation in Fortinet FortiOS via Malicious Security Fabric Upstream Device

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 up to and including 7.4.4, 7.2.0 up to and including 7.2.9 and prior to 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.

Solution

Please upgrade to FortiOS version 7.6.1 or above
Please upgrade to FortiOS version 7.4.5 or above
Please upgrade to FortiOS version 7.2.10 or above
Please upgrade to FortiOS version 7.0.16 or above

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortios 7.6.0

fortinet fortios 7.4.4

fortinet fortios 7.4.3

fortinet fortios 7.4.2

fortinet fortios 7.4.1

fortinet fortios 7.4.0

fortinet fortios 7.2.9

fortinet fortios 7.2.8

fortinet fortios 7.2.7

fortinet fortios 7.2.6

fortinet fortios 7.2.5

fortinet fortios 7.2.4

fortinet fortios 7.2.3

fortinet fortios 7.2.2

fortinet fortios 7.2.1

fortinet fortios 7.2.0

fortinet fortios 7.0.15

fortinet fortios 7.0.14

fortinet fortios 7.0.13

fortinet fortios 7.0.12

fortinet fortios 7.0.11

fortinet fortios 7.0.10

fortinet fortios 7.0.9

fortinet fortios 7.0.8

fortinet fortios 7.0.7

fortinet fortios 7.0.6

fortinet fortios 7.0.5

fortinet fortios 7.0.4

fortinet fortios 7.0.3

fortinet fortios 7.0.2

fortinet fortios 7.0.1

fortinet fortios 7.0.0

fortinet fortios 6.4.15

fortinet fortios 6.4.14

fortinet fortios 6.4.13

fortinet fortios 6.4.12

fortinet fortios 6.4.11

fortinet fortios 6.4.10

fortinet fortios 6.4.9

fortinet fortios 6.4.8

fortinet fortios 6.4.7

fortinet fortios 6.4.6

fortinet fortios 6.4.5

fortinet fortios 6.4.4

fortinet fortios 6.4.3

fortinet fortios 6.4.2

fortinet fortios 6.4.1

fortinet fortios 6.4.0

fortinet fortios