Description
An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via reusing the session of a deleted user in the REST API.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Please upgrade to FortiOS version 7.4.0 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-31726 | An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via reusing the session of a deleted user in the REST API. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-028 |
|
History
Tue, 22 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-22T20:41:43.447Z
Reserved: 2023-03-09T10:09:33.120Z
Link: CVE-2023-28001
Updated: 2024-08-02T12:23:30.802Z
Status : Modified
Published: 2023-07-11T17:15:12.883
Modified: 2024-11-21T07:53:54.557
Link: CVE-2023-28001
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD