SB20241112148 - SSL-VPN session hijacking in FortiOS 



SB20241112148 - SSL-VPN session hijacking in FortiOS

Published: November 12, 2024

Security Bulletin ID SB20241112148
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Session fixation (CVE-ID: CVE-2023-50176)

The vulnerability allows a remote attacker to hijack victim's session.

The vulnerability exist due to a session fixation issue when handling SAML authentication. A remote attacker can trick the victim into clicking on a specially crafted SAML authentication link and hijack the user's session.

Successful exploitation of the vulnerability may allow an attacker to gain unauthorized access to the network with the privileges of the hijacked user account.


Remediation

Install update from vendor's website.