CVE-2024-27779: Session still active for deleted admin
An insufficient session expiration vulnerability [CWE-613] in FortiSandbox & FortiIsolator may allow a remote attacker in possession of an admin session cookie to keep using that admin's session even after the admin user was deleted.
Other sources
An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2 all versions and FortiIsolator version 2.4 and below, 2.3 all versions, 2.2 all versions, 2.1 all versions, 2.0 all versions, 1.2 all versions may allow a remote attacker in possession of an admin session cookie to keep using that admin's session even after the admin user was deleted.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27779?
CVE-2024-27779 has a critical severity level due to the potential for unauthorized access using an admin session cookie after the admin user has been deleted.
How do I fix CVE-2024-27779?
To remediate CVE-2024-27779, update FortiSandbox to version 4.4.5 or higher and FortiIsolator to version 2.4.5 or higher.
What products are affected by CVE-2024-27779?
CVE-2024-27779 affects FortiIsolator versions 2.0 to 2.4.4 and FortiSandbox versions 3.2 to 4.4.4.
Can CVE-2024-27779 be exploited remotely?
Yes, CVE-2024-27779 can be exploited remotely by an attacker possessing a valid admin session cookie.
What could happen if CVE-2024-27779 is not fixed?
If CVE-2024-27779 is not addressed, unauthorized users may gain prolonged access to admin functions even after the corresponding admin account has been deleted.