Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID via other, hypothetical attacks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Fortinet FortiDeceptor 代码问题漏洞
Vulnerability Description
Fortinet FortiDeceptor是美国飞塔(Fortinet)公司的一款网络威胁检测平台。该平台主要通过欺骗技术暴露网络威胁等。 Fortinet FortiDeceptor 3.0.0及之前版本中存在安全漏洞,该漏洞源于程序注销后,会话ID不过期。攻击者可借助未过期的管理员用户会话ID利用该漏洞获取管理员权限。
CVSS Information
N/A
Vulnerability Type
N/A