QID 43984
Date Published: 2023-02-22
QID 43984: FortiOS Padding Oracle In Cookie Encryption Vulnerability (FG-IR-21-126)
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiOS, FortiWeb, FortiProxy and FortiSwitch may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter.
Affected Versions:
FortiOS versions 7.0.3 and below
FortiOS versions 6.4.8 and below
FortiOS 6.2 all versions
FortiOS 6.0 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-21-126
Vendor References
- FG-IR-21-126 -
www.fortiguard.com/psirt/FG-IR-21-126
CVEs related to QID 43984
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-126 |
|