FG-IR-23-493: Administrator cookie leakage
An insufficiently protected credentials vulnerability (CWE-522) in FortiOS and FortiProxy may allow an attacker to obtain the administrator cookie in rare and specific conditions, via tricking the administrator into visiting a malicious attacker-controlled website through the SSL-VPN.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-493?
The FG-IR-23-493 vulnerability is classified with a medium severity rating.
How do I fix FG-IR-23-493?
To fix FG-IR-23-493, update FortiOS or FortiProxy to the remedial versions or later: FortiOS 7.4.2, 7.2.7, 7.0.13, 6.4.15, 6.2.16, and FortiProxy 7.4.2, 7.2.8, 7.0.14.
Which versions of FortiOS are affected by FG-IR-23-493?
Affected versions of FortiOS include 7.4.0 to 7.4.1, 7.2.0 to 7.2.6, 7.0.0 to 7.0.12, 6.4.0 to 6.4.14, and 6.2.0 to 6.2.15.
Is FortiProxy affected by FG-IR-23-493?
Yes, FortiProxy versions 7.4.0 to 7.4.1, 7.2.0 to 7.2.7, and 7.0.0 to 7.0.13 are affected by FG-IR-23-493.
What type of vulnerability is FG-IR-23-493?
FG-IR-23-493 is classified as an insufficiently protected credentials vulnerability, specifically CWE-522.