vulnerability

Fortinet FortiClientEMS: CVE-2023-45581: FortiClientEMS - Improper privilege management for site super administrator

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
Feb 8, 2024
Added
Nov 20, 2024
Modified
Jul 2, 2025

Description

An improper privilege management vulnerability [CWE-269] in FortiClientEMS graphical administrative interface may allow an Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via crafted HTTP or HTTPS requests.

Solution

fortinet-forticlientems-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.