A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-23-475 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
12 Dec 2024, 19:27
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-23-475 - Vendor Advisory | |
| CPE | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | |
| First Time |
Fortinet
Fortinet fortios |
12 Nov 2024, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-11-12 19:15
Updated : 2024-12-12 19:27
NVD link : CVE-2023-50176
Mitre link : CVE-2023-50176
JSON object : View
Products Affected
fortinet
- fortios
CWE
CWE-384
Session Fixation
