Impact
An improper restriction of communication channel to intended endpoints in Fortinet FortiSIEM Windows Agent 7.4.0 through 7.4.1 allows a malicious actor to potentially obtain higher privileges on the host. The weakness is classified as CWE‑923, indicating that the agent fails to enforce secure communication boundaries, which could enable exploitation of the privileged privilege chain. The advisory notes that an escalation of privilege may be possible but does not provide a concrete attack vector, so the exact path of exploitation remains unspecified.
Affected Systems
Fortinet FortiSIEM Windows Agent versions 7.4.0 and 7.4.1 are affected. Users running these versions are at risk and should consider upgrading to 7.4.2 or later, where the flaw is fixed.
Risk and Exploitability
The CVSS score of 6.9 denotes a moderate risk. The EPSS score is below 1%, indicating that observed exploitation is currently rare. The vulnerability is not listed in CISA’s KEV catalog. Because the advisory does not specify the attack vector, whether the issue can be exploited remotely or only locally is uncertain, but any exploitation would grant elevated privileges, justifying caution.
OpenCVE Enrichment