Description


An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks)

Related CPE's


a

fortinet

forticlient_endpoint_management_server

2

Weaknesses



CWE-613

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

8.1 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-10-06T08:15:07.713Z

4 years ago

Last modified

2024-11-21T04:52:13.237Z

1 year ago