QID 44084
Date Published: 2023-07-14
QID 44084: FortiOS - Insufficient Session Expiration Vulnerability in FortiOS REST API (FG-IR-23-028)
An insufficient session expiration [CWE-613] vulnerability in FortiOS REST API may allow an attacker to reuse the session of a deleted user, should the attacker manage to obtain the API token.
Affected Versions:
FortiOS version 7.2.0 through 7.2.4
FortiOS 7.0 all versions
QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.
Note: Making this QID practice as this QID is only supported for Fortios product also banner based detection added
Vulnerable versions of FortiOS may allow an attacker to reuse the session of a deleted user, should the attacker manage to obtain the API token.
Solution
Fortinet has released patch addressing the vulnerability. For more information please refer to FG-IR-23-028
Vendor References
- FG-IR-23-028 -
www.fortiguard.com/psirt/FG-IR-23-028
CVEs related to QID 44084
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-028 |
|