CVE-2023-41673: Fortinet FortiADC

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low privileged user to read or backup the full system configuration via HTTP or HTTPS requests.

Affected products

  • Fortinet FortiADC: from 6.0.0, up to and including 6.0.4; from 6.1.0, up to and including 6.1.6; from 6.2.0, up to and including 6.2.6; from 7.0.0, up to and including 7.0.5; version 7.1.0 only; version 7.1.1 only; …

Published 2023-12-13. Last modified 2026-06-17.