CVE-2024-27782

Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations vi

Severity
High 7.7
CVSS 3.1
Remote · no auth what this means
Exploited
Not listed
EPSS
0.007
52.6th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jul 9, 2024
Assigned by fortinet

Description

Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests.

Weakness: CWE-613

Affected products

Vendor Product Category Matched by
Fortinet FortiAIOps Network & Security Management cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiAIOps
  • fortinet · fortiaiops

Credit

Internally discovered and reported by Shripal Rawal of Fortinet PSIRT team.

Vendor remediation

Upgrade to FortiAIOps version 2.0.1 or above

Something wrong here?