QID 44035
Date Published: 2023-05-31
QID 44035: FortiOS Padding Oracle In Cookie Encryption Vulnerability (FG-IR-21-126) (Unauthenticated Check)
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiOS, FortiWeb, FortiProxy and FortiSwitch may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter.
Affected Versions:
FortiOS versions 7.0.3 and below
FortiOS versions 6.4.8 and below
FortiOS 6.2 all versions
FortiOS 6.0 all versions
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS.
Successful exploitation of the vulnerability may allow an attacker to decrypt portions of the administrative session management cookie if able to intercept the latter.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-21-126
Vendor References
- FG-IR-21-126 -
www.fortiguard.com/psirt/FG-IR-21-126
CVEs related to QID 44035
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-126 |
|