Fortinet FortiOS SSL-VPN Insufficient Session Expiration Vulnerability

Vulnerability

A vulnerability allowing insufficient session expiration has been identified in Fortinet FortiOS SSL-VPN. This issue is present in versions 7.6.0, 7.4.6 and below, 7.2.10 and below, all versions of 7.0, and all versions of 6.4. The vulnerability may allow an attacker with a valid cookie from an expired or logged-out session to reauthenticate and gain access to the SSL-VPN portal.

Impact

Exploitation of this vulnerability could lead to unauthorized access to the SSL-VPN portal by allowing an attacker to reuse an expired session cookie for reauthentication.

Added: Jun 10, 2025, 6:39 PM
Updated: Jun 10, 2025, 6:39 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
0.6
exploitability
7.0
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.