CVE-2020-6649: Critical severity fortinet fortiisolator vulnerability
An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6649?
CVE-2020-6649 is an insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below.
How does CVE-2020-6649 affect FortiNet's FortiIsolator?
CVE-2020-6649 allows an attacker to reuse unexpired admin user session IDs to gain admin privileges, if they obtain the session ID through other attacks.
What is the severity of CVE-2020-6649?
CVE-2020-6649 has a severity rating of 9.8, which is classified as critical.
How can I fix CVE-2020-6649?
To fix CVE-2020-6649, it is recommended to upgrade FortiNet's FortiIsolator to a version above 2.0.1.
Where can I find more information about CVE-2020-6649?
More information about CVE-2020-6649 can be found on the FortiGuard advisory page at https://fortiguard.com/advisory/FG-IR-20-011.