CVE-2025-62631
An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to main
Severity
Medium 5.3
CVSS 3.1
Exploited
Not listed
EPSS
0.003
20.7th percentile
Discovered by
Not disclosed
Published
Dec 9, 2025
Assigned by fortinet
Description
An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to maintain access to network resources via an active SSLVPN session not terminated after a user's password change under particular conditions outside of the attacker's control
Weakness: CWE-613
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiOS
Vendor remediation
Upgrade to FortiOS version 7.6.4 or above Upgrade to FortiOS version 7.4.8 or above