Multiple privilege escalation

Summary

An improper privilege management vulnerability [CWE 269] in FortiManager and FortiAnalyzer may allow a local attacker to escalate their privileges by abusing incorrect filesystem permissions

Version Affected Solution
FortiAnalyzer 7.6 Not affected Not Applicable
FortiAnalyzer 7.4 7.4.0 through 7.4.3 Upgrade to 7.4.4 or above
FortiAnalyzer 7.2 7.2.0 through 7.2.5 Upgrade to 7.2.6 or above
FortiAnalyzer 7.0 7.0 all versions Migrate to a fixed release
FortiAnalyzer 6.4 6.4 all versions Migrate to a fixed release
FortiAnalyzer Cloud 7.4 7.4.1 through 7.4.2 Upgrade to 7.4.3 or above
FortiAnalyzer Cloud 7.2 7.2.1 through 7.2.6 Upgrade to 7.2.7 or above
FortiAnalyzer Cloud 7.0 7.0 all versions Migrate to a fixed release
FortiAnalyzer Cloud 6.4 6.4 all versions Migrate to a fixed release
FortiManager Cloud 7.4 7.4.1 through 7.4.3 Upgrade to 7.4.4 or above
FortiManager Cloud 7.2 7.2.1 through 7.2.5 Upgrade to 7.2.7 or above
FortiManager Cloud 7.0 7.0 all versions Migrate to a fixed release
FortiManager 7.6 Not affected Not Applicable
FortiManager 7.4 7.4.0 through 7.4.3 Upgrade to 7.4.4 or above
FortiManager 7.2 7.2.0 through 7.2.5 Upgrade to 7.2.6 or above
FortiManager 7.0 7.0 all versions Migrate to a fixed release
FortiManager 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security Team.

Timeline

2025-01-14: Initial publication