<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Multiple VPN applications insecurely store session cookies</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-19-110</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2019-04-23T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2019-04-23T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2019-04-23T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            The Missing Encryption Of Sensitive Data vulnerability in FortiClient may allow an attacker to access VPN session cookie from an endpoint device running FortiClient. The attacker can steal the cookies only if endpoint device has been compromised in such a way that the attacker has access to FortiClient&#39;s debug logs or memory space. Furthermore, practical use of the stolen cookie requires the attacker to spoof the endpoint&#39;s IP address.
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="2">
            Information disclosure
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="3">
            FortiClient for Windows (6.2.0 and earlier)FortiClient for Mac OSX (6.2.0 and earlier)
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="4">
            Fortigate by default mitigates the session cookie misuse exploits mentioned above by verifying the source IP of client&#39;s request. As a precautionary measure, please upgrade to upcoming:FortiClient for Windows 6.2.2FortiClient for Mac OSX 6.2.2
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:DocumentReferences>
        <cvrf:Reference>
            <cvrf:URL>https://fortiguard.fortinet.com/psirt/FG-IR-19-110</cvrf:URL>
            <cvrf:Description>Multiple VPN applications insecurely store session cookies</cvrf:Description>
        </cvrf:Reference>
        <cvrf:Reference>
            <cvrf:URL>https://www.kb.cert.org/vuls/id/192371/</cvrf:URL>
            <cvrf:Description>https://www.kb.cert.org/vuls/id/192371/</cvrf:Description>
        </cvrf:Reference>
    </cvrf:DocumentReferences>
    <Vulnerability Ordinal="1">
        <Title>Multiple VPN applications insecurely store session cookies</Title>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>4.0</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:X/RC:X</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-19-110</URL>
                <Description>Multiple VPN applications insecurely store session cookies</Description>
            </Reference>Reference>
            <Reference>
                <URL>https://www.kb.cert.org/vuls/id/192371/</URL>
                <Description>https://www.kb.cert.org/vuls/id/192371/</Description>
            </Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>