Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-33507

Опубликовано: 14 окт. 2025
Источник: nvd
CVSS3: 7.4
CVSS3: 9.1
EPSS Низкий

Описание

An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker to deauthenticate logged in admins via crafted cookie and remote authenticated read-only attacker to gain write privilege via crafted cookie.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:fortinet:fortiisolator:*:*:*:*:*:*:*:*
Версия от 2.3.0 (включая) до 2.4.5 (исключая)

EPSS

Процентиль: 40%
0.00186
Низкий

7.4 High

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 7.4
github
4 месяца назад

An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker to deauthenticate logged in admins via crafted cookie and remote authenticated read-only attacker to gain write privilege via crafted cookie.

EPSS

Процентиль: 40%
0.00186
Низкий

7.4 High

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-613