High severity8.8NVD Advisory· Published Feb 15, 2024· Updated Jun 17, 2026
CVE-2023-45581
CVE-2023-45581
Description
An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via crafted HTTP or HTTPS requests.
Affected products
3- cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*Range: <7.0.10
7.2.0 through 7.2.2 and before 7.0.10+ 1 more
- (no CPE)range: 7.2.0 through 7.2.2 and before 7.0.10
- (no CPE)range: 7.2.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-23-357nvdVendor Advisory
News mentions
0No linked articles in our index yet.