FortiClientEMS - Improper privilege management for site super administrator

Summary

An improper privilege management vulnerability [CWE-269] in FortiClientEMS graphical administrative interface may allow an Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via crafted HTTP or HTTPS requests.

Version Affected Solution
FortiClientEMS 7.2 7.2.0 through 7.2.2 Upgrade to 7.2.3 or above
FortiClientEMS 7.0 7.0.6 through 7.0.10 Upgrade to 7.0.11 or above
FortiClientEMS 7.0 7.0.0 through 7.0.4 Upgrade to 7.0.11 or above
FortiClientEMS 6.4 6.4 all versions Migrate to a fixed release
FortiClientEMS 6.2 6.2 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Théo Leleu of Fortinet Product Security team.

Timeline

2024-02-06: Initial publication