Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortideceptor  >> 1.0  Security Vulnerabilities
A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0, 4.0.0 through 4.0.2 and before 3.3.3 allows a remote authenticated attacker to perform unauthorized API calls via crafted HTTP or HTTPS requests.
CVSS Score
8.8
EPSS Score
0.007
Published
2023-04-11
An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID via other, hypothetical attacks.
CVSS Score
8.1
EPSS Score
0.004
Published
2020-06-22


Contact Us

Shodan ® - All rights reserved