CVE-2023-50176

EUVD-2023-54998
A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.2 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 33.27%
Affected Products (NVD)
VendorProductVersion
fortinetfortios
7.0.0 ≤
𝑥
< 7.0.14
fortinetfortios
7.2.0 ≤
𝑥
< 7.2.8
fortinetfortios
7.4.0 ≤
𝑥
< 7.4.4
𝑥
= Vulnerable software versions