Improper Verification of Cryptographic Signature in FortiOS - CVE-2021-43074
Published: February 17, 2023
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to improper verification of cryptographic signature when handling cookie files. A remote user can decrypt portions of the administrative session management cookie (padding oracle in cookie encryption) and escalate privileges on the device.
Affected software
FortiProxy
FortiSwitch
FortiWeb
How to mitigate CVE-2021-43074
FortiProxy - addressed in versions 2.0.8, 7.0.7
FortiSwitch - addressed in versions 6.4.11, 7.0.4
FortiWeb - addressed in versions 6.3.17, 7.0.0