PT-2024-8775 · Fortinet · Fortios

CVE-2023-50176

·

Published

2024-11-12

·

Updated

2024-12-12

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Fortinet FortiOS versions 7.0.0 through 7.0.13 Fortinet FortiOS versions 7.2.0 through 7.2.7 Fortinet FortiOS versions 7.4.0 through 7.4.3
Description: A session fixation issue in Fortinet FortiOS allows an attacker to execute unauthorized code or commands via a phishing SAML authentication link. This vulnerability is related to the SSL VPN technology and can be exploited by a remote attacker to hijack a user's session. The exploitation may allow the attacker to perform arbitrary code execution or execute arbitrary commands.
Recommendations: For Fortinet FortiOS versions 7.0.0 through 7.0.13, update to a version that includes the fix for this issue. For Fortinet FortiOS versions 7.2.0 through 7.2.7, update to a version that includes the fix for this issue. For Fortinet FortiOS versions 7.4.0 through 7.4.3, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the SAML authentication link to minimize the risk of exploitation.

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10390
CVE-2023-50176

Affected Products

Fortios