Improper Verification of Cryptographic Signature in FortiOS - CVE-2021-43074

 

Improper Verification of Cryptographic Signature in FortiOS - CVE-2021-43074

Published: February 17, 2023


Vulnerability identifier: #VU72346
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-43074
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to improper verification of cryptographic signature when handling cookie files. A remote user can decrypt portions of the administrative session management cookie (padding oracle in cookie encryption) and escalate privileges on the device.



Affected software

FortiOS
FortiProxy
FortiSwitch
FortiWeb

How to mitigate CVE-2021-43074

Install updates from vendor's website.

FortiOS - addressed in versions 6.4.9, 7.0.7
FortiProxy - addressed in versions 2.0.8, 7.0.7
FortiSwitch - addressed in versions 6.4.11, 7.0.4
FortiWeb - addressed in versions 6.3.17, 7.0.0

External References

Related Security Bulletins