CVE-2024-50562
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker
Description
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.
Weakness: CWE-613
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
| Fortinet | FortiPAM | Identity / IAM / MFA | cna-assigner |
| Fortinet | FortiProxy | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported products (4)
- Fortinet · FortiOS
- Fortinet · FortiPAM
- Fortinet · FortiProxy
- Siemens · RUGGEDCOM APE1808
Credit
Fortinet is pleased to thank Vang3lis and Cyth from VARAS@IIE and Shahid Parvez Hakim CEO & Founder of Bugb Technologies (bugb.io) for reporting this vulnerability under responsible disclosure.
Vendor remediation
Please upgrade to FortiOS version 7.6.1 or above Please upgrade to FortiOS version 7.4.8 or above Please upgrade to FortiOS version 7.2.11 or above Please upgrade to FortiSASE version 24.4.c or above