Supers override fails to properly override supervisor address
MonitorCVSS 6.9FG-IR-26-155Jul 14, 2026
Fortinet
IT in OT - Fortinet products are commonly deployed at IT/OT network boundaries
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
The FortiSIEM Windows Agent installer contains a flaw in the supers override feature that fails to properly validate and enforce the intended supervisor address. An attacker with local network access could exploit this during agent installation or updates to redirect the agent to report to an unauthorized SIEM server, potentially intercepting security logs and evading detection.
What this means
What could happen
An attacker with network access to the FortiSIEM Windows Agent installation process could bypass the intended supervisor address override, potentially redirecting the agent to report to an attacker-controlled server instead of the legitimate SIEM. This could allow the attacker to intercept security logs and blind monitoring of the affected Windows systems.
Who's at risk
Windows systems running FortiSIEM Agent for log aggregation and security monitoring. This affects organizations using Fortinet's SIEM solution for centralized event collection, particularly those monitoring OT or critical infrastructure networks where log integrity and chain-of-custody are essential.
How it could be exploited
An attacker on the local network intercepts or manipulates the FortiSIEM Windows Agent installer during deployment or updates. By crafting a malicious override for the supervisor address, the attacker redirects the agent to a compromised SIEM server. The agent then sends all security events and logs to the attacker's server instead of the legitimate monitoring infrastructure, allowing the attacker to suppress alerts and cover their tracks.
Prerequisites
- Network access to the Windows system running FortiSIEM Agent
- Ability to interact with or manipulate the agent installer or configuration during deployment/update
- Access to the same network segment as the target system (local network required per CVSS Vector AV:A)
Requires local network accessLow attack complexityMedium CVSS scoreCould compromise security monitoring visibilityAffects log integrity and audit trails
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (1)
ProductAffected VersionsFix Status
FortiSIEMWindowsAgent7.4.0 - 7.4.17.4.2+
Remediation & Mitigation
0/4
Do now
0/2WORKAROUNDIf immediate patching is not possible, restrict network access to the Windows Agent installation/update process to authorized deployment servers only
HARDENINGMonitor agent configuration changes and verify that the supervisor address matches your legitimate SIEM server
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate FortiSIEM Windows Agent to version 7.4.2 or later
Long-term hardening
0/1HARDENINGImplement network segmentation to limit local network access to systems running FortiSIEM Agent
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/0c0467b9-e2cf-4451-825a-9be311793464Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.