{"id":"CVE-2023-50176","title":"A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.","summary":"A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-384"],"vendor":"fortinet","product":"fortios","affected":["fortios >= 7.0.0, < 7.0.14","fortios >= 7.2.0, < 7.2.8","fortios >= 7.4.0, < 7.4.4"],"patched":["fortios 7.4.4"],"published":"2024-11-12","updated":"2026-08-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-50176","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-23-475","label":"psirt@fortinet.com"}],"tags":["nvd"],"epss":0.00402,"epssPercentile":0.34112,"ingestedAt":"2026-08-24T14:04:34.086Z","slug":"CVE-2023-50176","body":"## Overview\n\nA session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.\n\n## Affected\n\n- `fortios >= 7.0.0, < 7.0.14`\n- `fortios >= 7.2.0, < 7.2.8`\n- `fortios >= 7.4.0, < 7.4.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fortios 7.4.4`","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}