QID 44180
Date Published: 2024-04-11
QID 44180: FortiOS Administrator Cookie Leakage Vulnerability (FG-IR-23-493)
An insufficiently protected credentials vulnerability in FortiOS and may allow an attacker to obtain the administrator cookie in rare and specific conditions, via tricking the administrator into visiting a malicious attacker-controlled website through the SSL-VPN.
Affected Versions:
FortiOS 7.4 Versions 7.4.0 through 7.4.1
FortiOS 7.2 Versions 7.2.0 through 7.2.6
FortiOS 7.0 Versions 7.0.0 through 7.0.12
FortiOS 6.4 Versions 6.4.0 through 6.4.14
FortiOS 6.2 Versions 6.2.0 through 6.2.15
FortiOS 6.0 all versions
QID Detection Logic (Authenticated):(LINUX)
Detection checks for vulnerable version of FortiOS.
QID Detection Logic (Unauthenticated):
Detection checks for vulnerable version of FortiOS via SNMP Banner.
Vulnerable version of FortiOS may allow an attacker to obtain the administrator cookie in rare and specific conditions, via tricking the administrator into visiting a malicious attacker-controlled website through the SSL-VPN.
- FG-IR-23-493 -
fortiguard.fortinet.com/psirt/FG-IR-23-493
CVEs related to QID 44180
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-493 |
|