PT-2021-4339 · Fortinet · Forticlientems

Published

2021-10-05

·

Updated

2021-10-14

·

CVE-2021-24019

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiClientEMS versions 6.4.2 and below FortiClientEMS versions 6.2.8 and below
Description The issue is related to insufficient session expiration, which may allow an attacker to reuse unexpired admin user session IDs and gain admin privileges if they can obtain the session ID. This could potentially be achieved through other hypothetical attacks.
Recommendations For FortiClientEMS versions 6.4.2 and below, consider restricting access to admin user sessions to minimize the risk of exploitation. For FortiClientEMS versions 6.2.8 and below, restrict access to admin user sessions until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04963
CVE-2021-24019

Affected Products

Forticlientems