
Cloud Vulnerability DB
A community-led vulnerabilities database
An insufficient session expiration vulnerability (CVE-2023-33303) was discovered in Fortinet FortiEDR Central Manager versions 5.0.0 through 5.0.1. The vulnerability was initially published on October 10, 2023, and is classified as High severity with a CVSSv3 score of 7.7. The vulnerability was discovered and reported by security researcher Kevin Carli under responsible disclosure (Fortinet Advisory).
The vulnerability is classified as CWE-613 (Insufficient Session Expiration) and affects the GUI component of FortiEDR. The issue allows an attacker to reuse unexpired user API access tokens to gain privileges, provided they can obtain the API access token through other hypothetical attacks (Fortinet Advisory, NVD).
If successfully exploited, this vulnerability allows attackers to execute unauthorized code or commands via API requests. The high CVSS score of 7.7 indicates significant potential impact on the system's confidentiality, integrity, and availability (Fortinet Advisory).
The vulnerability requires the attacker to first obtain the API access token through other means before they can exploit the insufficient session expiration issue. The attack complexity is considered high, but no authentication is required to exploit the vulnerability once the token is obtained (NVD).
Fortinet has released patches to address this vulnerability. Users are advised to upgrade to either FortiEDR version 5.2.0.2501 or above, or FortiEDR version 5.0.3.873 or above (Fortinet Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."