CVE Vulnerabilities

CVE-2023-50176

Session Fixation

Published: Nov 12, 2024 | Modified: Dec 12, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.

Weakness

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 7.0.0 (including) 7.0.14 (excluding)
Fortios Fortinet 7.2.0 (including) 7.2.8 (excluding)
Fortios Fortinet 7.4.0 (including) 7.4.4 (excluding)

Extended Description

Such a scenario is commonly observed when:

Potential Mitigations

References