FG-IR-23-028: Existing websocket connection persists after deleting API admin
An insufficient session expiration [CWE-613] vulnerability in FortiOS REST API may allow an attacker to keep a secure websocket session active after user deletion.## Workaround:Restrict hosts that can connect to the websocket to trusted ones only, with the trusted host feature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-028?
The severity of FG-IR-23-028 is considered high due to the risk of maintaining active sessions after user deletion.
How do I fix FG-IR-23-028?
To fix FG-IR-23-028, upgrade FortiOS to version 7.2.5 or above for the affected versions.
What causes the FG-IR-23-028 vulnerability?
FG-IR-23-028 is caused by an insufficient session expiration mechanism in the FortiOS REST API.
Who is affected by FG-IR-23-028?
Users with FortiOS versions 7.2.0 to 7.2.4 and 7.0.0 to 7.0.12 are affected by FG-IR-23-028.
What is the workaround for FG-IR-23-028?
The recommended workaround for FG-IR-23-028 is to restrict websocket connections to only trusted hosts.