PT-2021-4339 · Fortinet · Forticlientems
Published
2021-10-05
·
Updated
2021-10-14
·
CVE-2021-24019
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiClientEMS versions 6.4.2 and below
FortiClientEMS versions 6.2.8 and below
Description
The issue is related to insufficient session expiration, which may allow an attacker to reuse unexpired admin user session IDs and gain admin privileges if they can obtain the session ID. This could potentially be achieved through other hypothetical attacks.
Recommendations
For FortiClientEMS versions 6.4.2 and below, consider restricting access to admin user sessions to minimize the risk of exploitation.
For FortiClientEMS versions 6.2.8 and below, restrict access to admin user sessions until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forticlientems