---
cve: "CVE-2023-45581"
severity: "HIGH"
cvss: 7.9
epss: "82%"
vendor: "Fortinet"
kev: false
exploited: false
published: "2024-02-15 14:15:45"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-05T19:44:24+02:00"
---

# CVE-2023-45581

> 7.9 HIGH

## Beschreibung

An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via crafted HTTP or HTTPS requests.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:U
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-269** — Improper Privilege Management
  The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

## Angriffsmuster (CAPEC)

- [CAPEC-58 — Restful Privilege Elevation](https://capec.mitre.org/data/definitions/58.html) _(Severity: High)_
- [CAPEC-122 — Privilege Abuse](https://capec.mitre.org/data/definitions/122.html) _(Severity: Medium)_
- [CAPEC-233 — Privilege Escalation](https://capec.mitre.org/data/definitions/233.html)

## ATT&CK-Techniken

- [T1548 — Abuse Elevation Control Mechanism](https://attack.mitre.org/techniques/T1548/)

## Referenzen

- <https://fortiguard.com/psirt/FG-IR-23-357>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-45581) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
