Fortinet FortiOS SSL-VPN
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*
- 7.6.0
- 7.4.6
- ~7.2
- ~7.0
- ~6.4
A vulnerability allowing insufficient session expiration has been identified in Fortinet FortiOS SSL-VPN. This issue is present in versions 7.6.0, 7.4.6 and below, 7.2.10 and below, all versions of 7.0, and all versions of 6.4. The vulnerability may allow an attacker with a valid cookie from an expired or logged-out session to reauthenticate and gain access to the SSL-VPN portal.
Exploitation of this vulnerability could lead to unauthorized access to the SSL-VPN portal by allowing an attacker to reuse an expired session cookie for reauthentication.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.