CVE-2022-45862: GUI Console WebSockets do not terminate on logout
An insufficient session expiration vulnerability [CWE-613] in FortiOS, FortiProxy, FortiPAM & FortiSwitchManager GUI may allow attackers to re-use websessions after GUI logout, should they manage to acquire the required credentials.
Other sources
An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use websessions after GUI logout, should they manage to acquire the required credentials.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45862?
CVE-2022-45862 has been classified as a high severity vulnerability due to insufficient session expiration.
How do I fix CVE-2022-45862?
To fix CVE-2022-45862, upgrade to FortiOS version 7.2.6 or later, FortiProxy version 7.2 or later, FortiPAM version 1.4.0 or later, or FortiSwitchManager version 7.2.2 or later.
Which products are affected by CVE-2022-45862?
CVE-2022-45862 affects FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager across various versions.
What is an insufficient session expiration vulnerability in the context of CVE-2022-45862?
An insufficient session expiration vulnerability, like CVE-2022-45862, allows attackers to reuse web sessions after a user logs out if they obtain the necessary credentials.
Is remote exploitation possible with CVE-2022-45862?
Yes, CVE-2022-45862 could be exploited remotely if an attacker has access to the valid user credentials.