PT-2020-6786 · Fortinet · Fortideceptor

Published

2020-06-21

·

Updated

2020-06-29

·

CVE-2020-6644

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiDeceptor versions 3.0.0 and below
Description The issue is related to an insufficient session expiration in FortiDeceptor, which can be exploited by a remote attacker to gain elevated privileges using session IDs. This could potentially allow an attacker to reuse unexpired admin user session IDs and obtain admin privileges if they can obtain the session ID through other means.
Recommendations For FortiDeceptor versions 3.0.0 and below, consider restricting access to the system until a fix is available, and ensure that session IDs are properly secured to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06502
CVE-2020-6644

Affected Products

Fortideceptor