SB20241112148 - SSL-VPN session hijacking in FortiOS



SB20241112148 - SSL-VPN session hijacking in FortiOS

Published: November 12, 2024

Security Bulletin ID SB20241112148
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Session fixation (CVE-ID: CVE-2023-50176)

CWE-ID: CWE-384 - Session Fixation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to hijack victim's session.

The vulnerability exist due to a session fixation issue when handling SAML authentication. A remote attacker can trick the victim into clicking on a specially crafted SAML authentication link and hijack the user's session.

Successful exploitation of the vulnerability may allow an attacker to gain unauthorized access to the network with the privileges of the hijacked user account.


Remediation

Install update from vendor's website.