An insufficient session expiration vulnerability [CWE-613] in FortiEDR Central Manager may allow an attacker to reuse the unexpired user API access token to gain privileges, should the attacker be able to obtain that API access token (via other, hypothetical attacks).
FortiEDR version 5.0.0 through 5.0.1
Please upgrade to FortiEDR version 22.214.171.1241 or above
Please upgrade to FortiEDR version 126.96.36.1993 or above
AcknowledgementFortinet is pleased to thank security researcher Kevin Carli for discovering and reporting this vulnerability under responsible disclosure.
2023-09-29: Initial publication