FortiOS, FortiWeb, and FortiProxy Vulnerability Lets Attackers Bypass FortiCloud SSO Authentication
ID: e44efe27-7cb9-59cc-83dd-a017a1c93f81
STIX ID: report--e44efe27-7cb9-59cc-83dd-a017a1c93f81
Feed Name: cybersecurityNews.com
Threat Score
**Fortinet urgent advisory:** a critical SAML signature verification flaw (CWE-347) in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager can allow unauthenticated attackers to bypass FortiCloud SSO and obtain administrative access; Fortinet published affected versions, recommended upgrades, and advises disabling FortiCloud login as a temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
