CVE-2024-23663: Fortinet Fortiextender Firmware
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to create users with elevated privileges via a crafted HTTP request.
Affected products
- Fortinet Fortiextender Firmware: from 4.1.1, up to and including 4.1.9; from 4.2.0, up to and including 4.2.6; from 7.0.0, up to and including 7.0.4; from 7.2.0, up to and including 7.2.4; from 7.4.0, up to and including 7.4.2; version 5.3.2 only
Published 2024-07-09. Last modified 2026-06-17.