Lucene search

K
cvelistFortinetCVELIST:CVE-2020-6644
HistoryJun 22, 2020 - 3:23 p.m.

CVE-2020-6644

2020-06-2215:23:43
fortinet
www.cve.org
6

AI Score

8.1

Confidence

High

EPSS

0.002

Percentile

60.7%

An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID via other, hypothetical attacks.

CNA Affected

[
  {
    "product": "Fortinet FortiDeceptor",
    "vendor": "Fortinet",
    "versions": [
      {
        "status": "affected",
        "version": "3.0.0 and below"
      },
      {
        "status": "affected",
        "version": "Fixed in 3.0.1"
      }
    ]
  }
]

AI Score

8.1

Confidence

High

EPSS

0.002

Percentile

60.7%

Related for CVELIST:CVE-2020-6644