SB2025061113 - Insufficient Session Expiration in FortiOS
Published: June 11, 2025 Updated: June 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficient Session Expiration (CVE-ID: CVE-2024-50562)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to insufficient session expiration in SSL-VPN cookie. An attacker in possession of a cookie used can log in the SSL-VPN portal to log in again, although the session has expired or was logged out.
Remediation
Install update from vendor's website.