A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.
2024-11-12T19:15:07.360
2024-12-12T19:27:35.530
Analyzed
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | fortinet | fortios | < 7.0.14 | Yes |
Operating System | fortinet | fortios | < 7.2.8 | Yes |
Operating System | fortinet | fortios | < 7.4.4 | Yes |