QID 43984

Date Published: 2023-02-22

QID 43984: FortiOS Padding Oracle In Cookie Encryption Vulnerability (FG-IR-21-126)

An improper verification of cryptographic signature vulnerability [CWE-347] in FortiOS, FortiWeb, FortiProxy and FortiSwitch may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter. Affected Versions:
FortiOS versions 7.0.3 and below
FortiOS versions 6.4.8 and below
FortiOS 6.2 all versions
FortiOS 6.0 all versions

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Successful exploitation of the vulnerability may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-21-126
    Vendor References

    CVEs related to QID 43984

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-126 URL Logo www.fortiguard.com/psirt/FG-IR-21-126