Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-48715 | An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use websessions after GUI logout, should they manage to acquire the required credentials. |
Solution
Please upgrade to FortiOS version 7.4.0 or above Please upgrade to FortiOS version 7.2.6 or above Please upgrade to FortiPAM version 1.4.0 or above Please upgrade to FortiProxy version 7.4.0 or above Please upgrade to FortiSwitchManager version 7.2.2 or above
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-445 |
|
Thu, 22 Aug 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortios Fortinet fortipam Fortinet fortiproxy Fortinet fortiswitchmanager |
|
| CPEs | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet fortios Fortinet fortipam Fortinet fortiproxy Fortinet fortiswitchmanager |
Tue, 13 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Aug 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use websessions after GUI logout, should they manage to acquire the required credentials. | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-13T17:32:25.867Z
Reserved: 2022-11-23T14:57:05.613Z
Link: CVE-2022-45862
Updated: 2024-08-13T17:32:21.915Z
Status : Analyzed
Published: 2024-08-13T16:15:07.977
Modified: 2024-08-22T14:32:16.823
Link: CVE-2022-45862
No data.
OpenCVE Enrichment
No data.
EUVD