First published: Tue Jul 11 2023(Updated: )
An insufficient session expiration [CWE-613] vulnerability in FortiOS REST API may allow an attacker to keep a secure websocket session active after user deletion.## Workaround:Restrict hosts that can connect to the websocket to trusted ones only, with the trusted host feature.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | >=7.2.0<=7.2.4 | |
Fortinet FortiOS | >=7.0.0<=7.0.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.