Cookie security policy bypass

Summary

An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF) when cookie security policy is enabled may allow an attacker, under specific conditions, to retrieve the initial encrypted and signed cookie protected by the feature

Version Affected Solution
FortiADC 7.6 Not affected Not Applicable
FortiADC 7.4 7.4.0 through 7.4.4 Upgrade to 7.4.5 or above
FortiADC 7.2 7.2 all versions Migrate to a fixed release
FortiADC 7.1 7.1 all versions Migrate to a fixed release
FortiADC 7.0 7.0 all versions Migrate to a fixed release
FortiADC 6.2 6.2 all versions Migrate to a fixed release
FortiADC 6.1 6.1 all versions Migrate to a fixed release
FortiADC 6.0 6.0 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Tom Tervoort from Secura for reporting this vulnerability under responsible disclosure.

Timeline

2024-09-10: Initial publication