CVE-2023-44250: Fortinet FortiOS

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated actions via crafted HTTP or HTTPS requests.

Affected products

  • Fortinet FortiOS: version 7.2.5 only; version 7.4.0 only; version 7.4.1 only
  • Fortinet FortiProxy: version 7.4.0 only; version 7.4.1 only

Published 2024-01-10. Last modified 2026-06-17.