QID 377738
Date Published: 2022-11-09
QID 377738: FortiClient - SAML SSO Replay Attack Vulnerability (FG-IR-21-192)
An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS may allow an unauthenticated attacker to impersonate an existing user by intercepting and re-using valid SAML authentication messages.
Affected Products:
FortiClientEMS version 7.0.1 and below.
FortiClientEMS version 6.4.4 and below.
QID Detection Logic (Authenticated) :
This checks for vulnerable version of FortiClient.exe.
Vulnerable version may allow an unauthenticated attacker to impersonate an existing user by intercepting and re-using valid SAML authentication messages
Solution
Users are advised to upgrade to the latest version FortiClient. Please refer Forticlient Advisory for further information.
Vendor References
- FG-IR-21-192 -
www.fortiguard.com/psirt/FG-IR-21-192
CVEs related to QID 377738
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-192 |
|