PT-2020-6786 · Fortinet · Fortideceptor
Published
2020-06-21
·
Updated
2020-06-29
·
CVE-2020-6644
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiDeceptor versions 3.0.0 and below
Description
The issue is related to an insufficient session expiration in FortiDeceptor, which can be exploited by a remote attacker to gain elevated privileges using session IDs. This could potentially allow an attacker to reuse unexpired admin user session IDs and obtain admin privileges if they can obtain the session ID through other means.
Recommendations
For FortiDeceptor versions 3.0.0 and below, consider restricting access to the system until a fix is available, and ensure that session IDs are properly secured to prevent unauthorized access.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortideceptor