Описание
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.
Уязвимые конфигурации
Одно из
EPSS
4.8 Medium
CVSS3
Дефекты
Связанные уязвимости
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.
Уязвимость технологии SSL-VPN операционных систем FortiOS, позволяющая нарушителю обойти процесс аутентификации
EPSS
4.8 Medium
CVSS3