CVE-2023-33303
FortiEDR vulnerability analysis and mitigation

Overview

An insufficient session expiration vulnerability (CVE-2023-33303) was discovered in Fortinet FortiEDR Central Manager versions 5.0.0 through 5.0.1. The vulnerability was initially published on October 10, 2023, and is classified as High severity with a CVSSv3 score of 7.7. The vulnerability was discovered and reported by security researcher Kevin Carli under responsible disclosure (Fortinet Advisory).

Technical details

The vulnerability is classified as CWE-613 (Insufficient Session Expiration) and affects the GUI component of FortiEDR. The issue allows an attacker to reuse unexpired user API access tokens to gain privileges, provided they can obtain the API access token through other hypothetical attacks (Fortinet Advisory, NVD).

Impact

If successfully exploited, this vulnerability allows attackers to execute unauthorized code or commands via API requests. The high CVSS score of 7.7 indicates significant potential impact on the system's confidentiality, integrity, and availability (Fortinet Advisory).

Exploitability

The vulnerability requires the attacker to first obtain the API access token through other means before they can exploit the insufficient session expiration issue. The attack complexity is considered high, but no authentication is required to exploit the vulnerability once the token is obtained (NVD).

Mitigation and workarounds

Fortinet has released patches to address this vulnerability. Users are advised to upgrade to either FortiEDR version 5.2.0.2501 or above, or FortiEDR version 5.0.3.873 or above (Fortinet Advisory).

Additional resources


SourceThis report was generated using AI

Related FortiEDR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-33303HIGH8.1
  • FortiEDR logoFortiEDR
  • cpe:2.3:a:fortinet:fortiedr
NoYesOct 13, 2023
CVE-2022-23440HIGH7.8
  • FortiEDR logoFortiEDR
  • cpe:2.3:a:fortinet:fortiedr
NoYesApr 06, 2022
CVE-2023-44248MEDIUM5.5
  • FortiEDR logoFortiEDR
  • cpe:2.3:a:fortinet:fortiedr
NoYesNov 14, 2023
CVE-2022-39949MEDIUM5.5
  • FortiEDR logoFortiEDR
  • cpe:2.3:a:fortinet:fortiedr
NoYesNov 02, 2022
CVE-2022-29057MEDIUM5.4
  • FortiEDR logoFortiEDR
  • cpe:2.3:a:fortinet:fortiedr
NoYesJul 19, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management