CVE-2024-33507
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 a
Description
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker to deauthenticate logged in admins via crafted cookie and remote authenticated read-only attacker to gain write privilege via crafted cookie.
Weakness: CWE-613
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiIsolator | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiIsolator
Credit
Internally discovered and reported by Leslie Zhou of Fortinet Vulnerability Research team.
Vendor remediation
Upgrade to FortiIsolator version 3.0.0 or above Upgrade to FortiIsolator version 2.4.5 or above