CVE-2023-47539

CRITICAL

An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin log...

Affects 1 product across 1 vendor.

BCS6.5
CVSS 3.19.8
EPSS1.1%
Percentile61th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-284: Improper Access Control

Software does not restrict or incorrectly restricts access to a resource.

Related Attack Patterns (CAPEC)
CAPEC-478 Modification of Windows Service Configuration
via CWE-284
CAPEC-479 Malicious Root Certificate
via CWE-284
CAPEC-546 Incomplete Data Deletion in a Multi-Tenant Environment
via CWE-284
CAPEC-550 Install New Service
via CWE-284
CAPEC-551 Modify Existing Service
via CWE-284
Show all 17

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in FortiMail version 7.4.0 with RADIUS authentication and remote_wildcard enabled allows unauthenticated attackers to bypass admin login through a crafted HTTP request.

BSID: BS-2025-GLOBAL-014726-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2023-47539?
A critical vulnerability in FortiMail version 7.4.0 with RADIUS authentication and remote_wildcard enabled allows unauthenticated attackers to bypass admin login through a crafted HTTP request.
What is the CVSS score for CVE-2023-47539?
CVE-2023-47539 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 1.1%.
Is CVE-2023-47539 actively exploited?
No confirmed active exploitation of CVE-2023-47539 as of 2026-05-30.
How do I remediate CVE-2023-47539?
Priority: IMMEDIATE. Advisory: https://fortiguard.com/psirt/FG-IR-23-439 PSIRT: [email protected]
What systems are affected by CVE-2023-47539?
CVE-2023-47539 affects: Fortinet.
Vulnerability Details
CVE IDCVE-2023-47539
BSIDBS-2025-GLOBAL-014726-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2025-03-18
Last Modified2025-07-24
ICS Relevance70%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability stems from improper access control mechanisms, specifically when remote_wildcard is enabled. An attacker can exploit this by sending a specially crafted HTTP request to the FortiMail server, potentially gaining unauthorized administrative access.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Fortinet Fortimail
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 494 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashdb0ee59190f1c3b083a061ca572e79f444fc2f4cad80ecf4477df5952f9676b236cbd274825a7a297d6e82663f15fb62202b3ea4a6e016b9326ffd224f5c86bc
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2024-47575 9.8 A missing authentication for critical function in FortiManager 7.6.0, FortiMa... CVE-2024-23109 9.8 An improper neutralization of special elements used in an os command ('os com... CVE-2024-23108 9.8 An improper neutralization of special elements used in an os command ('os com... CVE-2019-16153 9.8 A hard-coded password vulnerability in the Fortinet FortiSIEM database compon...
View all Fortinet CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →