CVE-2023-41677: Administrator cookie leakage
A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17 allows attacker to execute unauthorized code or commands via targeted social engineering attack
Other sources
An insufficiently protected credentials vulnerability (CWE-522) in FortiOS and FortiProxy may allow an attacker to obtain the administrator cookie in rare and specific conditions, via tricking the administrator into visiting a malicious attacker-controlled website through the SSL-VPN.
— FortiGuard
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-41677?
CVE-2023-41677 has been classified as a critical vulnerability due to insufficiently protected credentials.
How do I fix CVE-2023-41677?
To fix CVE-2023-41677, upgrade FortiOS to version 7.4.2 or later, 7.2.7 or later, or 7.0.13 or later.
Which versions are affected by CVE-2023-41677?
CVE-2023-41677 affects FortiOS versions from 7.4.0 to 7.4.1, 7.2.0 to 7.2.6, and 7.0.0 to 7.0.12, among others.
Is FortiProxy impacted by CVE-2023-41677?
Yes, CVE-2023-41677 also affects multiple versions of FortiProxy, specifically versions from 7.4.0 to 7.4.1, 7.2.0 to 7.2.7, and others.
What are the potential risks of CVE-2023-41677?
The potential risks of CVE-2023-41677 include unauthorized access and compromise of sensitive information due to insufficient protection of credentials.