Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q59r-m5g9-6m54

Опубликовано: 14 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker to deauthenticate logged in admins via crafted cookie and remote authenticated read-only attacker to gain write privilege via crafted cookie.

An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker to deauthenticate logged in admins via crafted cookie and remote authenticated read-only attacker to gain write privilege via crafted cookie.

EPSS

Процентиль: 40%
0.00186
Низкий

7.4 High

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 7.4
nvd
4 месяца назад

An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker to deauthenticate logged in admins via crafted cookie and remote authenticated read-only attacker to gain write privilege via crafted cookie.

EPSS

Процентиль: 40%
0.00186
Низкий

7.4 High

CVSS3

Дефекты

CWE-613